Massive Data Breach Exposes 16 Billion Credentials from Apple, Facebook, Google, Telegram

Massive Data Breach Exposes 16 Billion Credentials from Apple, Facebook, Google, Telegram

N
News Editor 01
2026-07-08 17:18:16
Cybersecurity researchers uncover one of the largest data breaches in history, with 16 billion login credentials exposed from platforms including Apple, Facebook, Google, and Telegram, posing severe risks of account takeover and phishing.
data breachcybersecuritypersonal data protectionhacker attackcryptocurrency security

A staggering new breach has exposed 16 billion login credentials, serving as a stark warning to individuals and organizations about the escalating risks of data theft. Cybersecurity researchers at Cybernews disclosed on June 19 that they have uncovered one of the largest data breaches ever recorded, consisting of 16 billion exposed login credentials.

Unprecedented Scale and Source

The researchers stated that the enormous cache of data likely stems from a range of infostealer malware attacks that have harvested credentials from numerous online platforms, including social media sites, corporate networks, VPN services, developer portals, and government systems. The team has been closely monitoring the web since the beginning of the year, discovering 30 exposed datasets containing from tens of millions to over 3.5 billion records each. In total, the researchers uncovered an unimaginable 16 billion records.

How the Data Was Exposed

The datasets were temporarily accessible via unsecured Elasticsearch databases and object storage instances, allowing Cybernews to examine them before they were secured or removed. The data followed a standard format: URL, login credentials, and password, which aligns with the way modern infostealer malware collects information.

The researchers emphasized the scale of the breach, stating: “This is not just a leak – it’s a blueprint for mass exploitation. With over 16 billion login records exposed, cybercriminals now have unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing.” They added that the structure and freshness of the data indicate this is not merely recycled information but new, actionable intelligence.

Platforms Affected

Information in the leaked datasets opens the doors to pretty much any online service imaginable, from Apple, Facebook, and Google, to GitHub, Telegram, and various government services. One dataset referencing the Russian Federation contained over 455 million records, and another linked to Telegram included more than 60 million records. Despite overlapping entries, researchers could not determine the exact number of individuals affected.

Risks and Warnings

They cautioned that tokens, cookies, and metadata embedded in the records increase the danger for organizations lacking multi-factor authentication and strong credential management. Although the source of the leak remains unknown, experts warned that cybercriminals can leverage such massive datasets to intensify identity theft, phishing, and system intrusions. Cryptocurrency users, in particular, should be vigilant as many exchange and wallet services may be included in this breach – immediate password changes and enabling two-factor authentication are strongly advised.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.