LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › 24 Billion Credentials Exposed in Massive Infostealer Leak

CRITICAL severityReportedHow we verify

24 Billion Credentials Exposed in Massive Infostealer Leak: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·June 12, 2026
24 Billion Credentials Exposed in Massive Infostealer Leak

Reported June 12, 2026. Approximately billions people affected.

CRITICAL
Severity
billions
People affected
4
Data types exposed
June 12, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A massive infostealer leak exposing 24 billion credentials was reported on June 12, 2026. Check whether your email, username, or passwords appear in the exposed data and change any reused credentials immediately.

Severity & verification
CRITICAL severityReported
Plaintext passwords exposed.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
billions accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Researchers at Cybernews reported on June 12, 2026, the discovery of an 8.3 terabyte database holding roughly 24 billion records. The collection contained usernames, email addresses, plaintext passwords, and login URLs, and remained publicly accessible until it was removed. The scale indicates that billions of individuals may have records included.

Such a volume of exposed login data raises immediate questions about reuse of credentials across accounts and the ease with which attackers could test the information on other services. The incident underscores how aggregated datasets can surface long after the original compromises that produced them.

What happened

The database combined material from 36 separate datasets. Its contents originated from infostealer malware logs, Telegram channels, breach compilations, and additional sources. No single organization is identified as the source of the entire collection; instead, the records represent an aggregation of previously obtained credentials.

Public details on the precise timing of the original infections or compilations that fed the database are not disclosed. The researchers noted that the 8.3 TB file was taken offline after its exposure was identified.

How a breach like this happens

Infostealer malware typically installs on a device through malicious downloads, phishing attachments, or compromised websites. Once active, it extracts stored browser credentials, autofill data, and session tokens, then transmits them to operators who may sell or share the logs.

These logs are frequently repackaged on messaging channels or merged into larger compilations. When such collections are stored without access controls, they can be indexed by search engines or discovered by researchers, leading to public disclosure of the aggregated material.

Who is 24 Billion Credentials Exposed in Massive Infostealer Leak?

The name refers to the exposed dataset itself rather than a single company or service provider. No central organization is described in the available reporting as the custodian of the full collection. The records instead reflect credentials drawn from many unrelated services over time.

Because the material is an aggregate, the incident does not point to a failure at one defined entity. It illustrates the cumulative result of numerous separate credential-harvesting events that were later consolidated.

What was likely exposed

The reported contents include usernames, email addresses, plaintext passwords, and login URLs. These fields were present across the 24 billion records in the 8.3 TB database.

Further specifics on additional data fields, such as personal identifiers or financial details, are not disclosed in the available information. The exact overlap between these records and any individual’s current accounts therefore remains unconfirmed without direct checking against the dataset.

Why it matters

Plaintext passwords that have already circulated in prior leaks can be tested automatically against many online services. When the same password is reused, a single exposed record can open access to multiple accounts belonging to the same person.

For organizations, the appearance of their users’ credentials in such a compilation can increase support requests and the likelihood of account takeover attempts. Individuals face the practical task of identifying which passwords in the dataset are still active and replacing them.

What to do if you're exposed

Begin by changing passwords for any accounts whose credentials appear in known compilations, starting with those that protect email or financial access. Enable multi-factor authentication wherever it is offered, and avoid reusing passwords across services.

Readers can run a free exposure scan of their email address against public breach data to determine whether their information has appeared in previously reported incidents. Monitoring services and password managers can further reduce the chance of undetected reuse.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

56M Emails in June 2026 Stealer Logs Added to HIBPJune 15, 2026Veil#Drop Framework Delivers PureLog Infostealer via BlogspotJuly 1, 2026KDDI Breach Exposes Up to 14.2M Email Logins at 6 Japanese ISPsJune 23, 2026Dashlane Brute-Force Attack Downloads <20 Encrypted VaultsJune 2, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the 24 Billion Credentials Exposed in Massive Infostealer Leak →

Source: Cybernews

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram