Cybernews researchers discovered an exposed database containing 24 billion records, including usernames, email addresses, plaintext passwords, and login URLs. The data appears to come from infostealer malware logs, records stolen from infected devices and collected from Telegram channels, breach compilations, and other sources.
Key takeaways:
Cybernews researchers found an exposed Elasticsearch cluster containing 24 billion records and more than 8.3TB of data.
Most records appear to be infostealer logs, including usernames, emails, passwords, and login URLs.
The data came from 36 sources, including Telegram channels, breach compilations, and large “collections.”
Researchers cannot yet confirm how many records are duplicates or how many unique people were affected.
The database is no longer publicly exposed, but reused passwords may still put accounts at risk.
While data leaks spilling millions of records have become the norm, one involving 24 billion records, including usernames and passwords, is something else. That’s why the Cybernews research team had to triple-check their findings after uncovering over 8 terabytes of data exposed online.