24 Billion Stolen Records Exposed Online — Should You Be Worried?

24 Billion Stolen Records Exposed Online — Should You Be Worried?

You are currently viewing 24 Billion Stolen Records Exposed Online — Should You Be Worried?
A publicly accessible database containing 24 billion records included usernames, email addresses, plain text passwords, login URLs, and other stolen login data.

A massive online database containing 24 billion records was found publicly accessible. Here’s what happened, why it matters, and how you can better protect your personal information from future scams.

What Happened?

According to Cybernews, researchers found a database containing 24 billion records on June 12, 2026.

The database held more than 8.3 terabytes of information. It was stored in an Elasticsearch cluster, which is a system companies use to organize and search huge amounts of data quickly.

Cybernews said the database was no longer publicly accessible by June 15, 2026.

After the report was published, Cybernews learned the database belonged to a threat intelligence and breach monitoring platform. The data was left accessible because of a misconfiguration during a temporary migration.

A misconfiguration means a system setting was wrong. In simple terms, the database was not locked down the way it should have been.

Who Was Affected and What Data Was Accessed?

Cybernews said the database contained 24 billion records. Researchers could not confirm how many records were duplicates.

That means the exact number of affected people is not publicly known.

Most records appeared to be infostealer logs. Infostealer logs are records collected by harmful software that steals information from infected devices.

The leaked records included:

  • usernames
  • email addresses
  • passwords in plain text
  • login URLs
  • sources of the stolen login data

Plain text passwords are passwords stored in a readable form. That is dangerous because criminals do not need to decode them.

Cybernews said the records came from 36 sources. These included Telegram channels, previous breach collections, and database exports from live systems.

Some records also appeared to come from local database dumps. That usually means someone copied data from a database and saved it elsewhere.

Login details are valuable because many people reuse passwords. If one password was leaked, criminals may try it on email, banking, shopping, and social media accounts.

That means a leak like this can create risks long after the database is closed.

Many people may not know their information was exposed in this incident or in older breaches or data leaks.

If you are not sure whether your information was leaked somewhere, automatic monitoring can help you spot problems earlier. 

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

How Did This Database Grow So Large?

This was not a single company data leak. Instead, researchers believe someone collected information from many different sources over several years and stored it in one place.

The database appears to have been updated regularly with newly stolen credentials and older breach records. 

Researchers even found recent cybersecurity articles and vulnerability information inside it, suggesting whoever maintained the database was actively tracking new security incidents.

Keep your personal information scam-proof

Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.

Check my safety

3 Simple Ways to Better Protect Your Information

You cannot stop every data leak, but these simple habits can help protect your accounts and personal information:

1. Secure your email account

Your email connects to many of your online accounts. If someone gains access to it, they may be able to reset passwords elsewhere.

Use a strong password and turn on two-step verification (an extra security step that requires a second code). If you are not sure how to strengthen your account security, the Futureproof Email Protection tool can help.

Email Protection helps you create strong passwords and set up two-step verification to secure your account faster.

Person at a computer login screen, illustrating how strong passwords and two-step verification can help protect accounts after the 24 billion-record exposure.
Strong, unique passwords and two-step verification can make it harder for criminals to access your accounts, even if old login details were exposed.

2. Watch for messages that mention your personal details

Be careful with emails, texts, or calls that mention your email address, username, or account information.

Criminals often use leaked information to make their messages seem legitimate. If you receive an unexpected request for personal information, payment, or login credentials, contact the company directly through its official website before responding.

3. Keep your devices and browsers updated

Infostealer malware (malicious software that steals passwords and other personal information) often gets onto devices through unsafe downloads, fake software, infected attachments, or outdated apps.

Keep your computer, phone, browser, and security software updated. Updates often fix security weaknesses that criminals can use to steal information from your device.

Also be careful when downloading free tools, browser extensions, or files from websites you do not fully trust.

You Can Lower Your Risk Even If Your Password Was Leaked 

A database containing 24 billion records shows how much stolen information circulates online. 

The good news is that a leaked password does not automatically mean your account will be stolen. 

Strong passwords, two-step verification, software updates, and regular monitoring can greatly reduce your risk. 

Tools such as Futureproof can also help you identify potential problems earlier, giving you more time to secure your information and keep your accounts safe.