7 months ago

149 Million Credentials Leaked in Unprotected Database

149 Million Credentials Leaked in Unprotected Database
Massive breach exposes 149 million Instagram, Gmail, OnlyFans passwords: How to stay safe? · livemint.com

A big problem happened where 149 million usernames and passwords were found online without any protection.

This wasn't done by hackers but by a researcher who found the data was left open for anyone to see.

The passwords were from many big websites like Gmail, Instagram, Netflix, and even some government sites.

The data was collected by a sneaky computer program called malware.

The researcher told the people who were hosting the data, but it took a month for them to take it down.

During that time, more passwords were added.

To stay safe, people should check their devices for malware, use special programs to manage passwords, turn on extra security steps like two-factor authentication, and not use the same password for different sites.

Key facts

Total Exposed Credentials
149,404,754 unique logins and passwords
Data Size
96 GB of raw credential data
Email Accounts Affected
48 million Gmail, 4 million Yahoo, 1.5 million Outlook
Social Media Accounts Affected
17 million Facebook, 6.5 million Instagram, 780k TikTok, numerous X (Twitter)
Entertainment Accounts Affected
3.4 million Netflix, HBO Max, Disney+, Roblox
Financial & Government Accounts Affected
420k Binance, banking logins, government (.gov) domains
Malware Type
Infostealer malware
Hosting Suspension Time
1 month after reporting

Timeline

  1. AI's vulnerability hunt exposed its own security gaps.

  2. Companies' lax AI security left data at risk.

  3. Unchecked AI tools opened doors to sensitive data.

  4. Amazon server's unsecured storage exposed 149M usernames and passwords.

  5. Gmail, Instagram among platforms hit in month-long data breach.

Quotes

Jeremiah Fowler

Cybersecurity researcher

“The publicly exposed database was not password-protected or encrypted. It contained 149,404,754 unique logins and passwords, totalling a massive 96 GB of raw credential data. In a limited sampling of the exposed documents, I saw thousands of files that included emails, usernames, passwords, and the URL links to the login or authorisation for the accounts.”
republicworld.com

Sources

Related news