Back to Blog
critical severity June 17, 2026 · billions affected

24 Billion Credentials Exposed in Massive Infostealer Leak

Cybernews researchers discovered an 8.3TB database containing approximately 24 billion records with usernames, email addresses, plaintext passwords, and login URLs. The aggregated collection originated from infostealer malware logs, Telegram channels, breach compilations, and other sources across 36 datasets. The exposed database was publicly accessible before being taken down.

⚠ Were you affected?
Free email scanner — we check your address against 15.4B+ leaked records in 15 seconds.
Run free scan →
24 Billion Credentials Exposed in Massive Infostealer Leak
Data exposed:
  • passwords
  • credentials
  • emails
  • usernames

An enormous cache of 24 billion credentials surfaced in a publicly accessible 8.3 terabyte database, exposing usernames, email addresses, plaintext passwords, and login URLs for potentially billions of people worldwide.

Researchers at Cybernews identified the collection on June 17, 2026. The data originated from infostealer malware logs, Telegram channels, breach compilations, and 36 distinct datasets. The database remained openly available until it was taken down following public reporting. Industry research from sources such as DoxxScan™ continuous monitoring confirms the scale and nature of the incident as one of the largest credential exposures recorded.

This breach matters because the records contain plaintext passwords that require no cracking. If you reuse the same password across multiple services, attackers can immediately test your credentials on banking sites, email accounts, social media, and shopping platforms. For your family, the risk extends to shared email addresses, children’s accounts, and any login tied to the same household details. A single exposed credential can unlock medical records, school portals, or family photos stored in the cloud.

The doxxing and identity-chain implications are particularly concerning. Infostealer logs often capture not just one password but dozens of saved credentials, browser cookies, and autofill data from the same infected device. Attackers can link your email address to usernames on gaming platforms, forums, and social apps. Once those connections are mapped, it becomes straightforward to build a complete profile that includes your home address, phone number, and family members’ names. Credential leaks like this one frequently cascade into account takeovers that lead to harassment, extortion, or further data sales on underground markets.

What to do

  • Run a DoxxScan to map every link between your handles, emails, phone numbers, and real-world identity so you can see exactly what chains exist before attackers exploit them.
  • Rotate every password used on the breached services and any site where that same password was reused, then replace it with a unique passphrase stored in a password manager.
  • Enable continuous DoxxScan monitoring across 15.4 billion breach records and more than 100 platforms so the next time your information appears it is caught and addressed within hours rather than months.
  • Cover the entire household with DoxxScan family protection, which includes dependents and children’s gaming accounts that often chain back to the same email address or home network.
  • Let remediation specialists handle the takedown requests across data brokers and exposed profiles while you focus on securing your daily accounts.

The speed at which stolen credentials circulate means the difference between early containment and prolonged exposure can be measured in days. Starting with a clear map of your digital footprint and maintaining continuous oversight gives you and your family the best chance of staying ahead of the next leak. DoxxScan by GalaxyWarden delivers that continuous monitoring across 15.4B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and household coverage that explicitly includes children’s gaming accounts.

Source: https://cybernews.com/security/24-billion-credentials-data-leak/

Sources

Why this isn’t just another breach checker

A breach leaks your credentials. Then hackers chain those credentials to your address, family, phone, and employer using public broker sites. We’re the only tool built around that chain.

Free checker Tells you the breach happened. End of story. You’re still on 800+ broker sites.
$129+/yr Broker-removal services scrub the address but don’t see the breach — next leak re-exposes you.
GalaxyWarden Maps the chain. Cleans both halves. $19 one-shot. Closed loop.

⚠ Were you in this breach?

Free email scanner. We check your address against 15.4B+ leaked records in 15 seconds — then show you the $19 cleanup that removes you from the broker sites aggregating leaked data.

Check my email — free →
Close the chain attack

Both halves of the chain, cleaned once.

A breach put your credentials in 15.4B+ leaked records. Hackers chain that data to your address on 800+ broker sites. GalaxyWarden closes both halves for $19 once — no subscription required.

Clean both halves — $19 →
Free breach scan + 800+ broker letters + 30-day proof · one payment, no subscription
W Warden Plus — ongoing monitoring $9.99/mo
Warden Plus ($9.99/mo or $99/yr): weekly re-scans, breach alerts, AI Concierge, auto re-files on relisted brokers.