24 Billion Stolen Credentials Were Just Found in a Single Database. Here's What to Do in the Next 60 Minutes.
On June 12, 2026, security researchers discovered a publicly accessible database containing 24 billion records — usernames, email addresses, plaintext passwords, and the login URLs they unlock. The database is now offline. The credentials are not. Here's what this means for your business and the five actions to take right now.
The first thing the researchers did when they saw the number was check it again. Then they checked it a third time. Twenty-four billion records. More than 8.3 terabytes of data, stored in a publicly accessible Elasticsearch cluster discovered on June 12, 2026. The database contained usernames, email addresses, plaintext passwords, and the specific login URLs that those credentials could be used to access.
The database was taken offline by June 15 — three days after discovery. But the credentials did not disappear when the database went offline. They had already been circulating across 36 sources — Telegram channels, breach compilations, infostealer malware collections, and what appeared to be direct exports from compromised live systems — for months or years before anyone found the database. Taking the database offline removes one copy from one location. The credentials remain active in every channel they came from.
credential records in a single exposed database — discovered June 12, 2026
The vast majority are infostealer logs — usernames, passwords, and the specific services they unlock, harvested directly from infected devices. The database drew from 36 sources including cybercrime Telegram channels, historical breach compilations, and apparent live system exports. Researchers triple-checked the number. It held up.
What the database actually contained — and why it's different from a standard breach
Most data breaches steal credentials from one place. This database aggregated from 36 distinct sources across years of cybercrime activity. That distinction matters for understanding the risk.
The CVE vulnerability records are the detail that elevates this beyond a standard credential dump. Whoever assembled this database was cross-referencing stolen credentials against known software vulnerabilities — building a targeting system that matches which credentials unlock which services, then identifies which of those services have unpatched exploits. This isn't a credential dump for manual use. It's a credential-plus-exploit intelligence platform, maintained and updated through February 2026.
The infostealer detail that changes your MFA calculation
The vast majority of the 24 billion records are infostealer logs — data collected by malware that silently harvests credentials from infected devices. This is where the story diverges from the standard "change your password" advice in a way that most coverage hasn't addressed.
Infostealers don't just steal passwords. They steal active browser session cookies. A session cookie is the token that proves you're already logged in — the credential that bypasses the login page entirely. If an infostealer captured your session cookie while you were logged into your work email or your company's cloud storage, the attacker already has an authenticated session. Changing your password after the fact doesn't invalidate the session cookie. The attacker's authenticated session may still be active.
The five actions to take in the next 60 minutes
Run the HIBP domain search right now
Do this firstHaveIBeenPwned added 56.3 million email addresses from this dataset on June 15. Your employees' work emails may be in the results. A domain search shows every company email address that has appeared in known breach databases — including this one.
Force sign-out across all active sessions — not just password resets
Session cookies at riskBecause infostealers capture session cookies, a password change alone doesn't close the window. An attacker with a stolen session token can continue accessing the account even after the password is changed. Force a complete sign-out of all active sessions — invalidating every session token — before issuing a new password.
Audit devices for infostealer malware before resetting passwords
Source of the problemThe 24 billion records are primarily infostealer logs — data harvested from infected devices. If an employee's credentials appear in this dataset, their device may still be infected. Changing the password on a compromised device means the new password is immediately captured by the same malware.
Enable number matching on MFA
Configuration · FreeStandard push notification MFA doesn't protect against session cookie theft — because session cookies bypass authentication entirely. But number matching significantly raises the barrier for the credential-stuffing attacks that use the password-based records in this dataset. Both defenses address different parts of the same problem.
Move from periodic to continuous credential monitoring
The systemic fixThe database was actively updated through February 2026. New credentials from new infostealers are added continuously to databases like this one. A one-time check today tells you where your employees stood on June 15. It doesn't tell you where they'll stand when the next dataset is compiled.
The honest context — what 24 billion means and what it doesn't
The 24 billion number includes duplicates — potentially significant duplicates. Researchers could not fully deduplicate the dataset before it was taken offline. The same credential appearing across multiple breach compilations counts multiple times. The real number of unique individuals affected is lower than 24 billion, though researchers have no way to quantify by how much.
What the number does represent accurately: the scale of credential aggregation happening in cybercrime ecosystems right now. This isn't a single breach. It's a window into how much stolen credential data is in active circulation — being bought, sold, tested, and used against real business systems every day. The 17 billion figure this series has cited since Post #2 just got updated. The economy that produced both numbers hasn't slowed down between them.
The five actions above take 60 minutes. The HIBP domain search takes 60 seconds. The credential monitoring that makes this a one-time response rather than a recurring scramble takes one setup. The response that works is the one that runs continuously — not the one triggered by the next headline.
📚 Credential Security Series — Read the full series
Find out if your employees are in the 24 billion. Veriti Spottr's beta is free.
Get your CyberScore →
Comments
Post a Comment