Manila Times

Upholding Truth. Empowering the Philippines
Sunday, Dec 07, 2025

16 Billion Login Credentials Leaked in Unprecedented Cybersecurity Breach

Security researchers confirm freshly stolen passwords from dozens of platforms now circulating online
Security researchers have identified an unprecedented leak encompassing approximately 16 billion user credentials, marking the largest such exposure on record.

The newly discovered databases comprise some 30 distinct datasets, each containing tens of millions to several billion records.

The information is believed to be obtained via infostealer malware campaigns targeting browser-saved credentials, session data, and cookies in real time.

This collection includes login details from major tech platforms—among them Apple, Google, Facebook, GitHub, and Telegram—as well as from VPN services, developer portals, online marketplaces, and government systems.

Each record reportedly combines URL, username or email, and password, enabling direct reuse for phishing or credential-stuffing attacks.

Cybercrime analysts describe the dataset as largely new, rather than recycled from earlier breaches.

The presence of intact login sequences and freshly stolen session tokens is cited as evidence of active malware operations in 2025.

The leak is said to have surfaced across underground forums and marketplaces in plain-text form, elevating its potential for automated exploitation.

Additionally, broader industry analysis during 2024–25 has catalogued over 19 billion leaked passwords across more than 200 breaches, with only around 6 percent being unique.

A staggering 94 percent of the datasets comprised reused or common credentials, with examples such as “123456,” “password,” and “admin” appearing hundreds of millions of times.

The reuse of credentials across accounts enables high-volume automated attacks, commonly referred to as credential stuffing, which carry success rates of up to 2 percent per million attempted logins.

Weak passwords remain prevalent: around 42 percent of entries are only 8–10 characters long, and roughly 27 percent use solely lowercase letters and digits.

The root cause of the leak is ascribed to infostealer malware.

These tools infiltrate endpoints and harvest sensitive credentials before packaging them into standardized databases for distribution in criminal marketplaces.

Analysts warn that the scale and freshness of this leak create a “blueprint for mass exploitation,” with direct applicability to phishing, account takeover, identity theft, and enterprise intrusion campaigns.

Platforms across sectors—financial services, healthcare, social media, government—face heightened risk as attackers deploy automated login attempts using the leaked credentials.

In prior incidents, such as between April 2024 and April 2025, over 3 terabytes of raw leaked data were analysed, revealing the systemic vulnerability posed by credential reuse worldwide.

Research emphasises that even simple dictionary-style passwords enable rapid account breaches when combined with attacker-owned automation systems.

The leak also echoes earlier megabreaches, such as the “RockYou2024” archive containing nearly 10 billion passwords compiled from two decades of incident data.

However, the current 16 billion-credential exposure is distinguished by its proximity in time and volume of nascent threat intelligence.

This situation illustrates the expanding role of malware-based exfiltration in complementing traditional data breach strategies, and paints a picture of rapidly circulating credential data re-entering the attacker economy almost in real time.
AI Disclaimer: An advanced artificial intelligence (AI) system generated the content of this page on its own. This innovative technology conducts extensive research from a variety of reliable sources, performs rigorous fact-checking and verification, cleans up and balances biased or manipulated content, and presents a minimal factual summary that is just enough yet essential for you to function as an informed and educated citizen. Please keep in mind, however, that this system is an evolving technology, and as a result, the article may contain accidental inaccuracies or errors. We urge you to help us improve our site by reporting any inaccuracies you find using the "Contact Us" link at the bottom of this page. Your helpful feedback helps us improve our system and deliver more precise content. When you find an article of interest here, please look for the full and extensive coverage of this topic in traditional news sources, as they are written by professional journalists that we try to support, not replace. We appreciate your understanding and assistance.
Newsletter

Related Articles

0:00
0:00
Close
Indian Airports in Turmoil as IndiGo Cancels Over a Thousand Flights, Stranding Thousands
Southeast Asia Floods Push Death Toll Above Nine Hundred as Storm Cluster Devastates Region
250 Still Missing in the Massive Fire, 94 Killed. One Day After the Disaster: Survivor Rescued on the 16th Floor
The Ukrainian Sumo Wrestler Who Escaped the War — and Is Captivating Japan
Families Accuse OpenAI of Enabling ‘AI-Driven Delusions’ After Multiple Suicides
China’s Wedding Boom: Nightclubs, Mountains and a Demographic Reset
A Decade of Innovation Stagnation at Apple: The Cook Era Critique
AI Researchers Claim Human-Level General Intelligence Is Already Here
Dick Cheney, Former U.S. Vice President, Dies at 84
U.S. Secures Key Southeast Asia Agreements to Reshape Rare Earth Supply Chains
US and China Agree One-Year Trade Truce After Trump-Xi Talks
United States and South Korea Conclude Major Trade Accord Worth $350 Billion
Amazon Announces 14 000 Corporate Job Cuts as AI Investment Accelerates
Philippines’ Taal Volcano Erupts Overnight with 2.4 km Ash Plume
U.S. Innovation Ranking Under Scrutiny as China Leads Output Outputs but Ranks 10th
Porsche Reverses EV Strategy as New CEO Bets on Petrol and Hybrids
Singapore’s Prime Minister Warns of ‘Messy’ Transition to Post-American Global Order
China Presses Netherlands to “properly” Resolve the Nexperia Seizure as Supply Chain Risks Grow
Japan stocks surge to record as Sanae Takaichi becomes Prime Minister
Hong Kong set to co-host China’s Fifteenth National Games in historic multi-city edition
"The Tsunami Is Coming, and It’s Massive": The World’s Richest Man Unveils a New AI Vision
Shenzhen Expo Spotlights China’s Quantum Step in Semiconductor Self-Reliance
China Accelerates to the Forefront in Global Nuclear Fusion Race
China Imposes Sanctions on South Korean Shipbuilder Over U.S. Ties
Russia Positions ASEAN Partnership as Cornerstone of Multipolar Asia at Kuala Lumpur Summit
AI and Cybersecurity at Forefront as GITEX Global 2025 Kicks Off in Dubai
EU Deploys New Biometric Entry/Exit System: What Non-EU Travelers Must Know
China Issues Policy Documents Exclusively in Domestic Office Format Amid Tech Tensions
Ex-Microsoft Engineer Confirms Famous Windows XP Key Was Leaked Corporate License, Not a Hack
China’s lesson for the US: it takes more than chips to win the AI race
The Davos Set in Decline: Why the World Economic Forum’s Power Must Be Challenged
Australian government pays Deloitte nearly half a million dollars for a report built on fabricated quotes, fake citations, and AI-generated nonsense.
US Prosecutors Gained Legal Approval to Hack Telegram Servers
FIFA Accuses Malaysia of Forging Citizenship Documents, Suspends Seven Footballers
Wave of Complaints Against Apple Over iPhone 17 Pro’s Scratch Sensitivity
Three Scientists Awarded Nobel Prize in Medicine for Discovery of Immune Self-Tolerance Mechanism
Foreign-Worker Housing Project in Kutchan Polarises Japan’s Demographic Debate
Central Asia’s Economies Poised for 6.1% Growth in 2025
India’s GST Collections Surge to ₹1.89 Lakh Crore in September
ADB Approves New Country Strategy to Boost Indonesia’s Growth
Indian Firms Take Lead in Electronics Manufacturing Push
Hong Kong Retains Third Place in Global Financial Centre Ranking
Malaysia Proposes Dual-Supply-Chain Strategy to Attract Investment
Chinese Economist Urges China-India Collaboration to Unlock Growth
Japanese Corporations Shift Toward Enhanced Shareholder Returns
ADB Signs First Sustainability-Linked Loan for Bangladesh Textile Sector
Hong Kong Retail Recovery Driven by Tourism Rebound
Japan’s Ruling Party Chooses Sanae Takaichi, Clearing Path to First Female Prime Minister
Sean ‘Diddy’ Combs Sentenced to Fifty Months in Prison Following Prostitution Conviction
Taylor Swift’s ‘Showgirl’ Launch Extends Billion-Dollar Empire
×