16 Billion Passwords Leaked: What Actually Happened and What to Do

A record-breaking cybersecurity incident in 2026 exposed over 16 billion login credentials—including passwords for Google, Facebook, Apple, Telegram, GitHub, and other services. The leaked data came from 30 structured infostealer malware logs and included recent and active credentials, not just old leaks. With such large-scale exposure, users and companies are now at higher risk of credential stuffing, phishing, account hijacking, and identity theft. Experts urge users to reset reused passwords, activate 2FA, and switch to passkeys immediately to stay secure.

Jun 21, 2025 - 12:05
Updated: 8 days ago
114.9k
16 Billion Passwords Leaked: What Actually Happened and What to Do

Quick answer: The "16 billion passwords" story, reported by Cybernews researchers in June 2025, describes about 30 exposed datasets of login records, mostly collected by infostealer malware and older leaks. It was not one breach of Google, Apple or Facebook. Your risk depends on password reuse, so use unique passwords, turn on multi-factor authentication and move to passkeys where offered.

Key takeaways

  • It was a pile of 30 datasets, reported in June 2025, not a hack of Google, Apple or Facebook itself.
  • Infostealer malware on infected devices is the likely source, which is why session cookies were also reported.
  • Password reuse is what turns a leak into an account takeover. Unique passwords stop that.
  • Use a password manager, enable MFA, prefer passkeys, and scan your own devices for infostealers.
  • For organisations: watch for credential stuffing and revoke sessions after any suspected infection.

What was reported

In June 2025, researchers at Cybernews reported finding around 30 databases that had been briefly exposed on misconfigured servers. Together they held roughly 16 billion records, and some single datasets were said to hold up to 3.5 billion. The records were structured as a link, a username and a password, covering services such as social media, email, VPNs, developer platforms and some government portals.

The original article of ours said the title year was 2026. That was a mistake: the reporting dates from June 2025. The figure itself comes from the researchers' own count and is not independently audited, so treat "16 billion" as the number of records, not the number of people.

Was this a new data breach?

No. Nobody broke into Google, Apple or Facebook. The data looks like a compilation: logs gathered by infostealer malware on infected personal and work devices, plus older credential-stuffing lists and earlier breaches. Many records are likely duplicates, and many passwords are probably already dead. That does not make it harmless. Fresh stealer logs are the most valuable kind of leaked data because they are recent.

How infostealers work

An infostealer is malware that quietly copies saved browser passwords, autofill data and session cookies, then uploads them to the attacker. It usually arrives through pirated software, fake installers, malicious ads or phishing attachments. Because it copies cookies, an attacker can sometimes reuse a logged-in session without ever typing your password, and without triggering your second factor.

Who is actually at risk?

You are at higher risk if you reuse passwords, store them in the browser on a shared or unpatched computer, or have installed cracked software. Attackers load leaked pairs into automated tools that try them on many sites. This is called credential stuffing. It works only where the same password is reused.

What to do today

  1. Check your exposure. Search your email addresses on a breach-notification service you trust, and note which accounts show up.
  2. Clean your device first. Run a full scan with a reputable security tool before you change passwords. Changing passwords on an infected machine only hands the new ones to the malware.
  3. Change reused passwords. Start with email, banking, and anything that can reset other accounts. Make each password unique and long.
  4. Use a password manager so unique passwords are practical.
  5. Turn on multi-factor authentication. An authenticator app or hardware key is stronger than SMS.
  6. Move to passkeys where a service supports them. A passkey cannot be typed into a fake site. See our post on Microsoft making passkeys the default.
  7. Sign out everywhere and revoke active sessions on important accounts, so stolen cookies stop working.

What organisations should do

Block logins from known-leaked passwords, apply rate limits and bot detection against credential stuffing, and require MFA with phishing-resistant methods for admins. Shorten session lifetimes for sensitive apps and invalidate sessions when a device is flagged. NIST's digital identity guidance in NIST Special Publications (SP 800-63B) recommends screening new passwords against lists of compromised ones instead of forcing frequent changes. If you suspect an incident in India, report it to CERT-In.

Common mistakes

  • Panic-changing passwords on a device that still has malware.
  • Assuming MFA makes stolen cookies harmless.
  • Reusing one "strong" password everywhere. Strong and reused is still weak.
  • Trusting any website that offers to "check if your password is leaked" without knowing who runs it. Never type your real password into such a tool.

Related reading: the large X (Twitter) records leak and the Samsung Germany data breach show how stolen credentials feed later attacks.

Next steps

Next steps: if you want to understand how attackers use stolen credentials and how defenders stop them, look at our Cyber Security course. The passkeys post is a good next read.

Frequently Asked Questions

It was real data but not a single breach. Researchers reported about 30 exposed datasets, largely infostealer logs and older leaks. No evidence shows Google, Apple or Facebook were hacked. Records are probably duplicated, so 16 billion does not mean 16 billion people.

Reports said records covered many services, including Apple, Google, Facebook, Telegram and GitHub. That means users of those services appear in the data, not that the companies were breached. Check your own accounts rather than relying on a company list.

Change passwords you have reused and any for email, banking and work first. Scan your device for malware before you do it. Unique passwords in a password manager plus MFA matter more than changing everything at once.

Sometimes. If a session cookie is stolen by an infostealer, an attacker may reuse the logged-in session without your password or code. Sign out of all sessions, clean the device and prefer passkeys or hardware keys.

Credential stuffing is when attackers automatically try leaked username and password pairs on many websites. It succeeds only when people reuse passwords. Unique passwords per site and MFA make it fail.

Signs include unexpected logins, new browser extensions and security alerts. Scan with a reputable anti-malware tool, review installed programs, and avoid cracked software. If unsure, back up files, reinstall the operating system and change passwords from a clean device.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.