Massive Leak Exposes 16 Billion Login Credentials Online

In a stark reminder of the scale of ongoing cybersecurity challenges, researchers have uncovered a leak of over 16 billion login credentials — including emails, passwords, and website addresses — that were temporarily exposed on the internet.

1 min read
AI generated image of a cyber attack with unrecognizable hooded hacker [Photo: FreePik]

Cybersecurity outlet Cybernews revealed that the data originated from 30 separate datasets discovered in recent months. While many of the credentials overlapped across datasets, the leak highlights the immense volume of personal information readily accessible to cybercriminals.

The leaked data includes login credentials for major platforms such as Apple, Facebook, Google, GitHub, Telegram, and even government services. Though the information was only exposed briefly — “long enough for researchers to uncover them, but not long enough to find who was controlling vast amounts of data,” Cybernews said — the potential damage remains significant.

Experts emphasize that attackers often exploit such leaks to gain unauthorized access to accounts, using brute-force attacks that rely on the widespread practice of password reuse. Additionally, leaked credentials can be weaponized for social engineering schemes, tricking users into divulging sensitive information.

Alan Woodward, a professor of cybersecurity at the University of Surrey, described the breach as part of a troubling new norm. “It’s really a demonstration of what has become the new paradigm in security: that you should assume any data stored digitally will be breached,” he said.

This shift has prompted a broader push within the tech industry toward “zero trust” security models, where even compromised data would remain unusable to malicious actors. As part of this evolution, companies are encouraging users to adopt passkeys — secure digital keys stored on individual devices — instead of traditional passwords.

Meta recently joined this trend, announcing that it will now support passkeys on Facebook in an effort to bolster account security.

Cyber experts also continue to recommend the use of password managers, which generate strong, unique credentials and store them in encrypted formats. However, these tools themselves can become attractive targets for hackers if not properly secured.

Two-factor authentication (2FA) remains another vital layer of defense, requiring users to verify their identity through a second method beyond just a password.

With Britain reportedly falling behind in its ability to respond to cyber threats — as noted by GCHQ — the latest breach underscores the urgent need for individuals and institutions alike to adopt robust security practices and remain vigilant in an increasingly hostile digital landscape.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog