Massive Data Breach: 23 Billion Credentials Exposed

Edited by: Tetiana Pinchuk Pinchuk

The cybersecurity service Have I Been Pwned (HIBP) integrated 23 billion stolen credentials from a malware operation named "ALIEN TXTBASE". This event is one of the largest data exposure events in its history.

The breach originated from a Telegram channel distributing "stealer logs." These logs contained 493 million unique website-email pairs and affected 284 million unique email addresses. Additionally, 244 million new passwords were added to HIBP’s Pwned Passwords database.

The stolen credentials encompass major services like Apple, Google, Facebook, Microsoft, and Twitter, as well as banks, cloud services, and government agencies. Users are advised to change passwords, enable two-factor authentication, and use unique, strong passwords.

Sources

  • Vorarlberg Online

  • Have I Been Pwned: Operation Endgame 2.0 Data Breach

  • Have I Been Pwned adds 284M accounts stolen by infostealer malware

  • Have I Been Pwned: Stealer Logs, Jan 2025 Data Breach

  • Have I Been Pwned: Check if your email address has been exposed in a data breach

Did you find an error or inaccuracy?

We will consider your comments as soon as possible.

Massive Data Breach: 23 Billion Credential... | Gaya One