16 Billion Login Credentials Leaked in Massive Data Breach Impacting Apple, Google and More

Apple, Facebook, Google, and Telegram are said to be some of the biggest companies to be impacted by this data breach.

Advertisement
Written by Shaurya Tomer, Edited by Siddharth Suvarna | Updated: 20 June 2025 12:28 IST
Highlights
  • Datasets comprising over 16 billion records were reportedly leaked
  • Leaked information included login credentials including passwords
  • Datasets came from stealer malware, old leaks, and credential dumps

The datasets reportedly contained from tens of millions to over 3.5 billion records each

Photo Credit: Reuters

Cybersecurity researchers have discovered a “mysterious database” comprising a staggering record of 16 billion login credentials, in what is being called one of the biggest data breaches in history. According to a report, it impacted some of the world's biggest technology companies including Apple, Facebook, and Google, along with government portals from multiple countries. The data breach gave threat actors brief but unprecedented access to personal credentials, posing risk of account takeover, identity theft, and phishing attacks.

Update: Telegram, in a statement to Gadgets 360, said, "Telegram's primary login method is a one-time-password delivered by SMS. As a result, this is far less relevant for Telegram users compared to other platforms where the password is always the same."

Advertisement

Billions of Login Credentials Leaked

According to a report by CyberNews, a majority of the data in the leaked database included information from credential stuffing sets, stealer malware, and repackaged leaks. Researchers say they've discovered 30 exposed datasets since the beginning of the year, comprising from tens of millions to over 3.5 billion records each, bringing the total to nearly 16 billion records which have been discovered so far.

Threat actors are speculated to have employed infostealer logs to steal this sensitive data. This breach impacted not just one company, sector, or country, but numerous ones. Apple, Facebook, Google, GitHub, and Telegram were some of the biggest companies to be impacted.

Advertisement

As per the report, it affected social media companies, corporate platforms, VPNs, developer portals, and even government services of various countries. Further, it is suggested that none of the datasets, except for one, were discovered in previous breaches, which means most of the data in the latest breach is fresh.

“What's especially concerning is the structure and recency of these datasets – these aren't just old breaches being recycled. This is fresh, weaponizable intelligence at scale”, the publication quoted researchers as saying.

Advertisement

The leaked data had a proper structure, with the URL followed by the login credentials and a password. As per the report, this is a staple method employed by threat actors to steal data. The smallest dataset reportedly had over 16 million records, while the largest one contained more than 3.5 billion. On an average, each dataset comprised 550 million exposed credentials.

Some of the datasets had generic names, such as “credentials” or “logins”. Meanwhile, others also reportedly referenced the services they were stolen from or related to. For example, researchers discovered one dataset named after Telegram which contained 60 million records.

Advertisement

The report states all of the datasets were only briefly exposed, but long enough for cybersecurity personnel to discover them. These were accessible through object storage instances or unsecured Elasticsearch. However, they could not uncover the entity controlling the 16 billion records.

Researchers say data breaches of this scale can be employed by threat actors for running phishing campaigns, taking over accounts, ransomware intrusions, and business email compromise (BEC) attacks.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. This AI Chatbot Can Help You Keep Track of Your Google Pay Payments
  2. Dell XPS 13 Launched in India Alongside New Dell 14S and Dell 16S Laptops
  3. Samsung Reportedly Increasing DDR4 RAM Production
  4. OpenAI's Rogue Agent Said to Have Compromised a Customer at a Second Tech Firm
  5. Redmi K100 Series Phone Visits Geekbench With This Flagship Snapdragon SoC
  6. Here's How Much the Vivo S2 Could Cost in India: See Expected Features
  7. JBL Bar 1000MK2 Review: More Than Just an Audio System
  8. Android 17 Beta Rolls Out to Motorola Edge 60 Pro With These Features
  9. Google Pixel Watch 5 Appears in Google Health App Ahead of August Launch
  10. Honor X6e Launched With 7,500mAh Battery
  1. Google Launches Gemini-Powered Ask Google Pay in India With a Dedicated In-App AI Chatbot
  2. OpenAI's Rogue Agent Compromised a Customer at a Second Tech Firm, Executive Says
  3. Honor X6e Launched With MediaTek Helio G81 Ultra SoC, 7,500mAh Battery: Price, Specifications
  4. Google Pixel Watch 5 Appears in Google Health App Ahead of August Launch
  5. Vivo S2 Price in India, Full Specifications, Design Spotted in Leaked Images Ahead on Launch
  6. Oppo Smartphone With Codename PYE110 Visits TENAA, Listing Suggests 8,000mAh Battery
  7. Samsung Galaxy Devices Get a New Security Feature With the Android 17 Update: Report
  8. Google Reportedly Rolling Out Gemini App UI Update With Easier Thinking Levels
  9. Samsung Expands RAM Production to Meet Rising Demand From Apple: Report
  10. PS Plus Monthly Games for August Announced: Dying Light 2 Stay Human: Reloaded Edition, Big Walk and Signalis
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.