Another month, another record: first it was 16 billion leaked credentials, then a database with 24 billion records found sitting in the open. Each time, the coverage sounds like a brand-new disaster. The reality is messier, more personal, and — usefully — more fixable.
What actually leaked
Researchers documented about 16 billion logins scattered across dozens of huge datasets, much of it collected by infostealer malware on infected devices. Their assessment pulled no punches: the data "opens the doors to pretty much any online service imaginable, from Apple, Facebook, and Google, to GitHub, Telegram, and various government services." Most records pair a site URL with a username and password — precisely what automated break-in tools want for breakfast.
It didn't stop there. In June 2026, a publicly exposed Elasticsearch database turned up holding 24 billion stolen credential records: 8.3 terabytes of usernames, emails, plaintext passwords, and login URLs. "Publicly exposed" is the alarming part. Nobody had to hack anything. Finding it was having it.
The number is inflated. The risk isn't.
Before you assume 24 billion victims: these mega-dumps are mostly combilists — the same old leaks from hundreds of past breaches, stitched together and topped up with fresher infostealer data. One stolen password can appear dozens of times across datasets. Records vastly outnumber actual people.
So no, this isn't billions of new hacks. But recycled loot spends just fine. Attackers pump these lists into credential-stuffing tools that fire your old leaked password at hundreds of other sites, automatically, around the clock. Reused a password in the last decade? Assume it's on a list, and assume software has already tried it somewhere.
Four moves, in order
Look yourself up. Have I Been Pwned — Troy Hunt's breach-lookup service — is still the gold standard. Type in your email, see which known breaches include you, and change those passwords first, along with anywhere else you reused them.
End password reuse. This one change breaks credential stuffing outright. CISA's bar: 16+ characters, random, mixed case with numbers and symbols, different for every single account. Nobody's memorizing fifty of those — that's what a password manager is for. Let it generate; let it remember.
Switch on multi-factor authentication wherever it exists. A password alone shouldn't unlock anything that matters. With MFA, a leaked credential is a failed attempt instead of a takeover.
Take the passkey option when sites offer it. Passkeys delete the whole category of risk: there's no reusable secret to steal. They can't be shared across sites, they're generated rather than guessed, and the private half stays on your device — a hacked website has nothing worth leaking.
And the quiet one: keep your devices clean
Remember where the fresh data comes from. Infostealers raid the passwords saved in your browser after riding in on sketchy downloads and cracked software. Every credential list starts on somebody's infected machine. Don't let it be yours — and think twice about letting the browser store the crown jewels unprotected.
The takeaway
There will be a bigger number next year; these piles only grow. Whether it touches you comes down to the boring stuff: unique passwords in a manager, MFA on, passkeys where possible, clean devices. An hour of setup, and the next record-breaking dump becomes news you skim instead of a week you lose.
Image: via Unsplash




