24 Billion Stolen Passwords in One Database: Inside the Industrial Infostealer Economy

https://hackernoon.imgix.net/images/rymeSO93fMg9m2SRdMsCXRtvbhG2-y3b3bk2.png

In June 2026, researchers at Cybernews found a single, publicly exposed Elasticsearch database holding more than 24 billion stolen credential records — over 8.3 terabytes of usernames, email addresses, plaintext passwords, login URLs, and source tags.

It was not a new breach. It was a consolidation: the aggregated output of years of infostealer infections, prior breach compilations, and criminal server exports, gathered into one searchable, structured trove and left sitting on the open internet with no password of its own.

The discovery is less a data-breach story than a milestone, marking the point at which stolen-credential theft stopped being a scattered nuisance and became an industrial supply chain.

What was found…

The exposed cluster was enormous and, crucially, well-organized. Most of the records traced back to infostealer malware — lightweight programs that quietly harvest saved logins, session cookies, and autofill data from infected devices and ship them to attackers. Analysts...

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more