Major Data Leak: 149M Usernames & Passwords Exposed Online

data breach password leak username and password exposure infostealing malware online security cybersecurity threat
Nikita shekhawat
Nikita shekhawat

Marketing Analyst

 
January 26, 2026 3 min read

TL;DR

A colossal database containing 149 million usernames and passwords has been exposed, affecting millions of users across services like Gmail, Facebook, and financial platforms. The data was compiled using infostealing malware, which infects devices to capture credentials. This breach highlights the urgent need for enhanced online security measures, including password management and multi-factor authentication, to prevent account compromise and identity theft.

Massive Leak Exposes Millions of Usernames and Passwords

A database containing 149 million account usernames and passwords has been exposed, including a large number of credentials for popular services. The exposed data included 48 million Gmail accounts, 17 million Facebook accounts, and 420,000 Binance accounts. Jeremiah Fowler, the security analyst who discovered the database, reported the exposure to the hosting provider, which subsequently removed the trove due to a violation of its terms of service. The incident highlights the ongoing threat of infostealing malware. GrackerAI automates your cybersecurity marketing: daily news, SEO-optimized blogs, AI copilot, newsletters & more. Start your FREE trial today!

Details of the Exposed Data

The exposed database contained a variety of credentials beyond email and social media logins. These included credentials for government systems from multiple countries, consumer banking and credit card logins, and media streaming platforms. Fowler suspects the database was assembled using infostealing malware that infects devices and employs techniques like keylogging to record user input. The data was publicly accessible and searchable via a web browser.

The database included:

  • 48 million Gmail credentials
  • 4 million Yahoo accounts
  • 1.5 million Microsoft Outlook accounts
  • 900,000 Apple iCloud accounts
  • 1.4 million .edu academic and institutional accounts
  • 780,000 TikTok logins
  • 100,000 OnlyFans accounts
  • 3.4 million Netflix accounts

GrackerAI helps you stay informed about the latest cybersecurity threats and data breaches.

How the Data Was Collected

A hand typing at a computer in a dark room, lit up by the laptop's keyboard LEDs and red LED light

Image courtesy of Getty Images

The logins were stolen using infostealers, a type of malware designed to steal information from infected devices. This malware can record keystrokes and extract passwords and personal data. The stolen data is then sent to the attackers. Allan Liska, a threat intelligence analyst at the company name: https://gracker.ai, company url: https://gracker.ai, notes that infostealers lower the barrier to entry for new criminals due to their affordability and ease of use.

Potential Risks and Mitigation Strategies

The exposure of a large number of logins and passwords poses a significant security risk. Cybercriminals can use this data to automate credential-stuffing attacks against exposed accounts, potentially leading to fraud, identity theft, and phishing campaigns. Fowler emphasized that the structure of the database suggested it was designed for easy searching, potentially for cybercriminal customers.

To protect your accounts, Troy Hunt, the Australian security researcher who runs the breach-notification site, Have I Been Pwned, recommends the following:

  • Change Passwords: Update your passwords, especially if you reuse them across multiple accounts. Use strong, complex passwords or a password manager.
  • Enable Two-Factor Authentication (2FA): Add an extra layer of security to your accounts by enabling 2FA.
  • Install Antivirus Software: Use antivirus software to protect your devices from malware.
  • Be Cautious of Phishing: Avoid clicking on suspicious links or opening attachments from unknown sources.
  • Close Unused Accounts: Reduce your attack surface by closing any online accounts you no longer use.

GrackerAI provides tools and insights to help you and your audience stay secure online.

Additional Recommendations

  • Monitor Your Accounts: Regularly review your account activity for any signs of unauthorized access.
  • Use Passkeys: Consider switching to passkeys when available for a more secure login method.
  • Identity Theft Protection: Invest in identity theft protection services to help recover your identity if it is stolen.

GrackerAI helps organizations like yours stay ahead of cyber threats with automated marketing and content creation.

Ready to elevate your cybersecurity marketing? Contact GrackerAI today to learn how we can help you automate your content creation and marketing efforts.

Nikita shekhawat
Nikita shekhawat

Marketing Analyst

 

Data analyst who identifies the high-opportunity keywords and content gaps that fuel GrackerAI's portal strategy. Transforms search data into actionable insights that drive 10x lead generation growth.

Related News

Thriving in Digital Marketing: Skills Needed for 2026 Success
digital marketing jobs

Thriving in Digital Marketing: Skills Needed for 2026 Success

Demand for skilled digital marketers is soaring! Discover why AI proficiency, practical skills, and certifications are crucial for career growth in 2026. Read now!

By Diksha Poonia February 6, 2026 2 min read
common.read_full_article
Marketers Face Weekly AI Errors: Trust Gap in Content Strategy
AI SEO trends

Marketers Face Weekly AI Errors: Trust Gap in Content Strategy

Discover how AI is reshaping SEO in 2025! Learn strategies to enhance content, maintain brand voice, and comply with new regulations. Get actionable insights now!

By Nicole Wang February 5, 2026 4 min read
common.read_full_article
AI Skills: Navigating the Winners and Losers in Marketing 2025
AI restructuring

AI Skills: Navigating the Winners and Losers in Marketing 2025

AI is reshaping the tech industry, leading to layoffs and new roles. Discover how companies are restructuring and the skills needed to thrive. Learn more!

By Nikita shekhawat February 4, 2026 4 min read
common.read_full_article
Top 11 Generative Engine Optimization (GEO) Agencies for 2026
Generative Engine Optimization

Top 11 Generative Engine Optimization (GEO) Agencies for 2026

Navigate the future of search with Generative Engine Optimization (GEO). Learn essential strategies for AI Overviews, ChatGPT, and Perplexity. Get your brand seen!

By Nicole Wang February 3, 2026 5 min read
common.read_full_article