Major Data Leak: 149M Usernames & Passwords Exposed Online

data breach password leak username and password exposure infostealing malware online security cybersecurity threat
Nikita shekhawat
Nikita shekhawat

Marketing Analyst

 
January 26, 2026 3 min read

TL;DR

  • A colossal database containing 149 million usernames and passwords has been exposed, affecting millions of users across services like Gmail, Facebook, and financial platforms. The data was compiled using infostealing malware, which infects devices to capture credentials. This breach highlights the urgent need for enhanced online security measures, including password management and multi-factor authentication, to prevent account compromise and identity theft.

Massive Leak Exposes Millions of Usernames and Passwords

A database containing 149 million account usernames and passwords has been exposed, including a large number of credentials for popular services. The exposed data included 48 million Gmail accounts, 17 million Facebook accounts, and 420,000 Binance accounts. Jeremiah Fowler, the security analyst who discovered the database, reported the exposure to the hosting provider, which subsequently removed the trove due to a violation of its terms of service. The incident highlights the ongoing threat of infostealing malware. GrackerAI automates your cybersecurity marketing: daily news, SEO-optimized blogs, AI copilot, newsletters & more. Start your FREE trial today!

Details of the Exposed Data

The exposed database contained a variety of credentials beyond email and social media logins. These included credentials for government systems from multiple countries, consumer banking and credit card logins, and media streaming platforms. Fowler suspects the database was assembled using infostealing malware that infects devices and employs techniques like keylogging to record user input. The data was publicly accessible and searchable via a web browser.

The database included:

  • 48 million Gmail credentials
  • 4 million Yahoo accounts
  • 1.5 million Microsoft Outlook accounts
  • 900,000 Apple iCloud accounts
  • 1.4 million .edu academic and institutional accounts
  • 780,000 TikTok logins
  • 100,000 OnlyFans accounts
  • 3.4 million Netflix accounts

GrackerAI helps you stay informed about the latest cybersecurity threats and data breaches.

How the Data Was Collected

A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light

Image courtesy of Getty Images

The logins were stolen using infostealers, a type of malware designed to steal information from infected devices. This malware can record keystrokes and extract passwords and personal data. The stolen data is then sent to the attackers. Allan Liska, a threat intelligence analyst at the company name: https://gracker.ai, company url: https://gracker.ai, notes that infostealers lower the barrier to entry for new criminals due to their affordability and ease of use.

Potential Risks and Mitigation Strategies

The exposure of a large number of logins and passwords poses a significant security risk. Cybercriminals can use this data to automate credential-stuffing attacks against exposed accounts, potentially leading to fraud, identity theft, and phishing campaigns. Fowler emphasized that the structure of the database suggested it was designed for easy searching, potentially for cybercriminal customers.

To protect your accounts, Troy Hunt, the Australian security researcher who runs the breach-notification site, Have I Been Pwned, recommends the following:

  • Change Passwords: Update your passwords, especially if you reuse them across multiple accounts. Use strong, complex passwords or a password manager.
  • Enable Two-Factor Authentication (2FA): Add an extra layer of security to your accounts by enabling 2FA.
  • Install Antivirus Software: Use antivirus software to protect your devices from malware.
  • Be Cautious of Phishing: Avoid clicking on suspicious links or opening attachments from unknown sources.
  • Close Unused Accounts: Reduce your attack surface by closing any online accounts you no longer use.

GrackerAI provides tools and insights to help you and your audience stay secure online.

Additional Recommendations

  • Monitor Your Accounts: Regularly review your account activity for any signs of unauthorized access.
  • Use Passkeys: Consider switching to passkeys when available for a more secure login method.
  • Identity Theft Protection: Invest in identity theft protection services to help recover your identity if it is stolen.

GrackerAI helps organizations like yours stay ahead of cyber threats with automated marketing and content creation.

Ready to elevate your cybersecurity marketing? Contact GrackerAI today to learn how we can help you automate your content creation and marketing efforts.

Nikita shekhawat
Nikita shekhawat

Marketing Analyst

 

Data analyst who identifies the high-opportunity keywords and content gaps that fuel GrackerAI's portal strategy. Transforms search data into actionable insights that drive 10x lead generation growth.

Related News

Highdive Appoints Megan Lally as CEO Amid Industry Buzz
Megan Lally CEO

Highdive Appoints Megan Lally as CEO Amid Industry Buzz

Highdive names Megan Lally its new CEO, marking a significant leadership transition. Discover her vision and the agency's recent successes. Read more!

By Ankit Lohar February 19, 2026 2 min read
common.read_full_article
Effective Market Research with ChatGPT: 28 Proven Prompts
ChatGPT market research

Effective Market Research with ChatGPT: 28 Proven Prompts

Unlock ChatGPT's potential for market research! Learn a structured workflow to enhance efficiency and accuracy while avoiding common AI pitfalls. Get actionable insights for your business.

By Hitesh Kumar Suthar February 18, 2026 9 min read
common.read_full_article
GTA 6 Release Delayed to November 2026 for Additional Polish
GTA 6 release date

GTA 6 Release Delayed to November 2026 for Additional Polish

GTA 6 delayed to November 19, 2026. Discover how this impacts other major game releases and Take-Two's financials. Read more!

By Ankit Lohar February 17, 2026 3 min read
common.read_full_article
AI Chatbots and Ads: Privacy Issues and Impact on Advertising
AI chatbots advertising

AI Chatbots and Ads: Privacy Issues and Impact on Advertising

AI chatbots are integrating ads, sparking privacy debates. Discover how this impacts advertising and what brands are doing. Learn more!

By Diksha Poonia February 16, 2026 2 min read
common.read_full_article