16 Billion Passwords Leaked: What Actually Happened and What to Do
A record-breaking cybersecurity incident in 2026 exposed over 16 billion login credentials—including passwords for Google, Facebook, Apple, Telegram, GitHub, and other services. The leaked data came from 30 structured infostealer malware logs and included recent and active credentials, not just old leaks. With such large-scale exposure, users and companies are now at higher risk of credential stuffing, phishing, account hijacking, and identity theft. Experts urge users to reset reused passwords, activate 2FA, and switch to passkeys immediately to stay secure.
Quick answer: The "16 billion passwords" story, reported by Cybernews researchers in June 2025, describes about 30 exposed datasets of login records, mostly collected by infostealer malware and older leaks. It was not one breach of Google, Apple or Facebook. Your risk depends on password reuse, so use unique passwords, turn on multi-factor authentication and move to passkeys where offered.
Key takeaways
- It was a pile of 30 datasets, reported in June 2025, not a hack of Google, Apple or Facebook itself.
- Infostealer malware on infected devices is the likely source, which is why session cookies were also reported.
- Password reuse is what turns a leak into an account takeover. Unique passwords stop that.
- Use a password manager, enable MFA, prefer passkeys, and scan your own devices for infostealers.
- For organisations: watch for credential stuffing and revoke sessions after any suspected infection.
What was reported
In June 2025, researchers at Cybernews reported finding around 30 databases that had been briefly exposed on misconfigured servers. Together they held roughly 16 billion records, and some single datasets were said to hold up to 3.5 billion. The records were structured as a link, a username and a password, covering services such as social media, email, VPNs, developer platforms and some government portals.
The original article of ours said the title year was 2026. That was a mistake: the reporting dates from June 2025. The figure itself comes from the researchers' own count and is not independently audited, so treat "16 billion" as the number of records, not the number of people.
Was this a new data breach?
No. Nobody broke into Google, Apple or Facebook. The data looks like a compilation: logs gathered by infostealer malware on infected personal and work devices, plus older credential-stuffing lists and earlier breaches. Many records are likely duplicates, and many passwords are probably already dead. That does not make it harmless. Fresh stealer logs are the most valuable kind of leaked data because they are recent.
How infostealers work
An infostealer is malware that quietly copies saved browser passwords, autofill data and session cookies, then uploads them to the attacker. It usually arrives through pirated software, fake installers, malicious ads or phishing attachments. Because it copies cookies, an attacker can sometimes reuse a logged-in session without ever typing your password, and without triggering your second factor.
Who is actually at risk?
You are at higher risk if you reuse passwords, store them in the browser on a shared or unpatched computer, or have installed cracked software. Attackers load leaked pairs into automated tools that try them on many sites. This is called credential stuffing. It works only where the same password is reused.
What to do today
- Check your exposure. Search your email addresses on a breach-notification service you trust, and note which accounts show up.
- Clean your device first. Run a full scan with a reputable security tool before you change passwords. Changing passwords on an infected machine only hands the new ones to the malware.
- Change reused passwords. Start with email, banking, and anything that can reset other accounts. Make each password unique and long.
- Use a password manager so unique passwords are practical.
- Turn on multi-factor authentication. An authenticator app or hardware key is stronger than SMS.
- Move to passkeys where a service supports them. A passkey cannot be typed into a fake site. See our post on Microsoft making passkeys the default.
- Sign out everywhere and revoke active sessions on important accounts, so stolen cookies stop working.
What organisations should do
Block logins from known-leaked passwords, apply rate limits and bot detection against credential stuffing, and require MFA with phishing-resistant methods for admins. Shorten session lifetimes for sensitive apps and invalidate sessions when a device is flagged. NIST's digital identity guidance in NIST Special Publications (SP 800-63B) recommends screening new passwords against lists of compromised ones instead of forcing frequent changes. If you suspect an incident in India, report it to CERT-In.
Common mistakes
- Panic-changing passwords on a device that still has malware.
- Assuming MFA makes stolen cookies harmless.
- Reusing one "strong" password everywhere. Strong and reused is still weak.
- Trusting any website that offers to "check if your password is leaked" without knowing who runs it. Never type your real password into such a tool.
Related reading: the large X (Twitter) records leak and the Samsung Germany data breach show how stolen credentials feed later attacks.
Next steps
Next steps: if you want to understand how attackers use stolen credentials and how defenders stop them, look at our Cyber Security course. The passkeys post is a good next read.
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0