Philiphall Massive Data Leak Exposes 24 Billion Credentials: Urgent Security Risks Identified
Article Content
- •24 billion records exposed, including plaintext usernames and passwords.
- •Data primarily sourced from infostealer malware and Telegram channels.
- •Users are urged to change passwords and enable multi-factor authentication.
Cybernews researchers uncovered an exposed Elasticsearch database containing 24 billion records, including usernames, email addresses, and plaintext passwords. The data is primarily sourced from infostealer malware logs and Telegram channels associated with cybercrime. The breach poses a significant risk to billions of accounts, especially those lacking multi-factor authentication. The exposed data includes records from 36 distinct sources, with over 1.7 billion records traced back to Telegram channels. The sheer volume of the leak, totaling over 8 terabytes, marks it as one of the largest credential leaks in history. Cybersecurity experts emphasize the urgent need for users to change passwords and enable multi-factor authentication to mitigate risks. The leak was discovered on June 12, 2026, and has raised alarms across the cybersecurity community.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Babuk, RedLine Stealer and Colonial Pipeline in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
NightEagle APT Targets Russian Enterprises with Advanced Malware The NightEagle APT group (APT-Q-95) has escalated its cyberattacks against Russian organizations, employing sophisticated techniques for persistence and lateral movement. Utilizing stolen credentials, the group gains access to corporate VPNs, often routing through Cloudflare WARP tunnels linked to Russian IPs. The…
Ransomware Exploits Critical VMware vCenter Vulnerability CVE-2026-59310 On September 15, 2026, CISA confirmed that ransomware gangs are actively exploiting a critical remote code execution vulnerability in VMware vCenter Server, tracked as CVE-2026-59310, which has a CVSS score of 9.8. This flaw, residing in the vCenter Syslog server, allows unauthenticated attackers with network access…