17.7 C
London
Saturday, June 20, 2026

‘Mother of all data breaches’ sees 16b passwords exposed

‘Mother of all data breaches’ sees 16b passwords exposed,

Cybersecurity researchers have uncovered what they are calling the ‘mother of all breaches.’

They discovered a massive collection of 30 databases containing more than 16 billion individual records, including passwords, for government accounts, Apple, Google, Facebook, Telegram and more websites. 

Some of the datasets had vague names like ‘logins’ or ‘credentials,’ which made it hard for the team to figure out exactly what they contained. 

Others, however, gave clues about where the data came from. 

According to the researchers, the records were most likely compiled by cybercriminals using various infostealing malware, though they noted that some data may also have been collected by so-called ‘white hat’ hackers.

The team at Cybernews, which found the records, said the information available to the wider internet was only briefly, before being locked down, but it is not possible to determine who owned the databases. 

With more than 5.5 billion people worldwide using the internet, researchers warned that a staggering number of individuals likely had at least some of their accounts compromised. 

They are now urging users across the globe to change their passwords immediately to protect their data from falling into the hands of cybercriminals. 

They found login credentials, including passwords, for government accounts, Apple, Google , Facebook, Telegram and more websites

‘The inclusion of both old and recent infostealer logs makes this data particularly dangerous for organizations lacking multi-factor authentication or credential hygiene practices,’ the researchers said.

Cybernews noted that its researchers identified a database of 184 million records that was previously uncovered in May, found by data breach hunter and security researcher Jeremiah Fowler.

‘It barely scratches the top 20 of what the team discovered,’ Cybernews explained. 

‘Most worryingly, researchers claim new massive datasets emerge every few weeks, signaling how prevalent infostealer malware truly is.’

The database of 184 million records not only contained secure login data for millions of private citizens, but also had stolen account information connected to multiple governments around the world.

While looking at a small sample of 10,000 of these stolen accounts, Fowler found 220 email addresses with .gov domains, linking them to more than 29 countries, including the US, UK, Australia, Canada, China, India, Israel, and Saudi Arabia.

‘This is probably one of the weirdest ones I’ve found in many years,’ Fowler told WIRED.

‘As far as the risk factor here, this is way bigger than most of the stuff I find, because this is direct access into individual accounts. This is a cybercriminal’s dream working list,’ the cybersecurity expert continued.

According to the researchers, the records were most likely compiled by cybercriminals using various infostealing malware , though they noted that some data may also have been collected by so-called 'white hat' hackers.

In total, Fowler discovered 47 gigabytes of data with sensitive information for accounts on various sites, including Instagram, Microsoft, Netflix, PayPal, Roblox, and Discord.

The best action to take right now is to change your passwords if you use any of these platforms and also activate Two-Factor Authentication, which adds another layer of security to logging in by sending a secure code to your phone or email.

The unprotected database was managed by World Host Group, a web hosting and domain name provider founded in 2019.

It operates over 20 brands globally, offering cloud hosting, domain services, and technical support for businesses of all sizes.

Once Fowler confirmed that the exposed information was genuine, he reported the breach to World Host Group, which shut down access to the database.

Seb de Lemos, CEO of World Host Group, told WIRED: ‘It appears a fraudulent user signed up and uploaded illegal content to their server.’

Fowler said ‘the only thing that makes sense’ is that the breach was the work of a cybercriminal because there’s no other way to gain that much access to information from so many servers around the world.

The cybersecurity expert warned that this particular breach also poses a major national security risk.

Exploiting government email accounts could allow hackers and foreign agents access to sensitive or even top-secret systems.

The stolen data could also be used as part of a larger phishing campaign, using one person’s hacked account to gain private information from other potential victims.

Cybersecurity researchers have uncovered what they are calling the ‘mother of all breaches.’

Hot this week

Diana’s ex-hairdresser condemns ‘evil’ comments about Kate’s hair

Princess Diana's former hairdresser has condemned 'nasty' comments made about the Princess of Wales 's hair - as she stepped out with her newly blonde tresses.

Experts reveal how many tins of tuna is safe to eat a week

The NHS advises people to eat at least two portions of fish a week, yet a recent investigation revealed toxic metals, including mercury, could be lurking in cans of tinned tuna sold in the UK.

The best places to live in Britain’s idyllic national parks

Many of us toy with the idea of moving somewhere close to nature, with a friendly community, where the pace of life is more civilised. But where to find such a place? A national park could be the answer.

The unusual breakfast request Princess Lilibet asks Meghan Markle for

Meghan Markle revealed her children's favourite meals and that she 'doesn't like baking' on the second season of her lifestyle show With Love, Meghan.

Some people DO see ghosts – and medics say there’s an explanation

An astonishing third of people in the UK and almost half of Americans say they believe in ghosts, spirits and other types of paranormal activity.

No Pulisic, no problem! Dominant USA breeze past Australia to seal World Cup knockout spot… as Seattle goes wild and fans start to dream...

USA 2-0 AUSTRALIA - DANIEL MATTHEWS IN SEATTLE: One huge step into the knockout rounds and one giant question answered: How would the USA cope without the injured Christian Pulisic?

Burnham ally Louise Haigh to Starmer: Leave quietly or face a ‘brutal, unpleasant’ fight for Labour leadership

At Mr Burnham's victory rally in Makerfield, Ms Haigh said: 'I hope the Prime Minister takes the weekend to really reflect on the result here.'

Burnham ally Louise Haigh to Starmer: Leave quietly or face a ‘brutal, unpleasant’ fight for Labour leadership

At Mr Burnham's victory rally in Makerfield, Ms Haigh said: 'I hope the Prime Minister takes the weekend to really reflect on the result here.'

No Pulisic, no problem! Dominant USA breeze past Australia to seal World Cup knockout spot… as Seattle goes wild and fans start to dream...

USA 2-0 AUSTRALIA - DANIEL MATTHEWS IN SEATTLE: One huge step into the knockout rounds and one giant question answered: How would the USA cope without the injured Christian Pulisic?

QUENTIN LETTS: At last the change the public needed. He ditched that terrible black T-shirt… just a shame about the moobs

At his victory shindig he wore a white polo shirt, untucked at the waist, hoping to disguise his moobs. And yet a brief outline of 56-year-old male nipple was glimpsed.

QUENTIN LETTS: At last the change the public needed. He ditched that terrible black T-shirt… just a shame about the moobs

At his victory shindig he wore a white polo shirt, untucked at the waist, hoping to disguise his moobs. And yet a brief outline of 56-year-old male nipple was glimpsed.

‘It feels like emotional blackmail’: As Harry and Meghan announce return to Britain with Archie and Lilibet, insiders say they fear decision to bring...

Both William and Harry's children are growing fast, but the last time they were even in the same country was four years ago, in June 2022. Californian-born Lili was just one year old.

‘It feels like emotional blackmail’: As Harry and Meghan announce return to Britain with Archie and Lilibet, insiders say they fear decision to bring...

Both William and Harry's children are growing fast, but the last time they were even in the same country was four years ago, in June 2022. Californian-born Lili was just one year old.
spot_img

Related Articles

Popular Categories

spot_imgspot_img