Massive Data Breach: 16 Billion Login Credentials Exposed, Apple, Facebook, Google, Telegram Affected

Massive Data Breach: 16 Billion Login Credentials Exposed, Apple, Facebook, Google, Telegram Affected

N
News Editor 01
2026-07-08 17:14:14
Cybersecurity researchers have uncovered one of the largest data breaches in history, exposing 16 billion login credentials from major platforms including Apple, Facebook, Google, and Telegram, posing severe risks of identity theft and phishing.
data breachcybersecuritylogin credentialsAppleGoogleTelegram

A colossal cybersecurity incident has sent shockwaves across the globe: over 16 billion login credentials have been exposed, giving cybercriminals unprecedented access to personal accounts, corporate networks, and government systems.

The Scale of the Breach: 16 Billion Records and Counting

On June 19, 2025, the cybersecurity research team at Cybernews disclosed what they describe as one of the largest data breaches ever recorded. The massive cache consists of approximately 16 billion compromised login credentials, collected from a wide range of online platforms including Apple, Facebook, Google, GitHub, Telegram, and numerous government services. The data was aggregated from multiple infostealer malware campaigns that have been harvesting credentials globally.

According to the researchers, “This is not just a leak – it’s a blueprint for mass exploitation. With over 16 billion login records exposed, cybercriminals now have unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing.” They emphasized that the data is fresh and structured, indicating it is not recycled old information but actionable intelligence.

How the Data Was Found and What It Contains

Cybernews has been monitoring the web since early 2025 and discovered 30 exposed datasets stored on unsecured Elasticsearch databases and object storage instances. These datasets range in size from tens of millions to over 3.5 billion records each. The data follows a standard format: URL, login credentials, and password — typical of modern information-stealing malware. Some datasets are labeled generically as “logins” or “credentials,” while others hint at their origin. For example, one dataset linked to the Russian Federation contains over 455 million records, and another associated with Telegram includes over 60 million records.

Due to overlapping entries, researchers cannot determine the exact number of individuals affected. However, they warned that tokens, cookies, and metadata embedded in the records increase the danger, especially for organizations lacking multi-factor authentication and strong credential management protocols.

Global Implications and Urgent Call to Action

The scope of this breach is staggering. Cybernews stated, “Information in the leaked datasets opens the doors to pretty much any online service imaginable, from Apple, Facebook, and Google, to GitHub, Telegram, and various government services. It’s hard to miss something when 16 billion records are on the table.” Although the exact source of the leak remains unknown, experts warn that cybercriminals can leverage this massive dataset to intensify identity theft, phishing campaigns, and system intrusions on an industrial scale.

This incident serves as a stark reminder for both individuals and organizations to adopt robust security measures immediately: enable multi-factor authentication, use strong and unique passwords, employ password managers, and remain vigilant against suspicious emails and links. In the digital age, data is oil, and a breach of this magnitude could fuel cyberattacks for years to come.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.