Massive Data Leak Exposes 24 Billion Credentials: Urgent Security Risks Identified

Massive Data Leak Exposes 24 Billion Credentials: Urgent Security Risks Identified

First seen 17 Jun 2026, 15:25 UTC CybernewsPhiliphallDailymailFeeds.FeedburnerGadgetreview+6 87% similarity 69.9

Article Content

Browse articles
ThreatCluster

Cybernews researchers uncovered an exposed Elasticsearch database containing 24 billion records, including usernames, email addresses, and plaintext passwords. The data is primarily sourced from infostealer malware logs and Telegram channels associated with cybercrime. The breach poses a significant risk to billions of accounts, especially those lacking multi-factor authentication. The exposed data includes records from 36 distinct sources, with over 1.7 billion records traced back to Telegram channels. The sheer volume of the leak, totaling over 8 terabytes, marks it as one of the largest credential leaks in history. Cybersecurity experts emphasize the urgent need for users to change passwords and enable multi-factor authentication to mitigate risks. The leak was discovered on June 12, 2026, and has raised alarms across the cybersecurity community.

Key Points: • 24 billion records exposed, including plaintext usernames and passwords. • Data primarily sourced from infostealer malware and Telegram channels. • Users are urged to change passwords and enable multi-factor authentication.

ThreatCluster AI How this analysis works

Timeline

2026-06-12
Discovery of massive data leak
Cybernews researchers found an Elasticsearch database containing 24 billion exposed records, including sensitive credentials.
Cybernews
2026-06-17
Public disclosure of data leak
Cybernews published findings on the colossal credential leak, warning users of potential account takeovers.
Cybernews
2026-06-17
Security community response
Experts emphasize the need for immediate password changes and multi-factor authentication to protect affected accounts.
Philiphall

Community

Browse all →