In June 2025 researchers reported discovering 30 unsecured datasets containing approximately 16 billion credential records — described as the largest such exposure recorded. The records were structured by site, username and password, spanning consumer platforms, VPNs, developer portals and government services.
The material was characterised as a mixture of recent infostealer logs, credential-stuffing compilations and repackaged older breaches. Some reporting noted the inclusion of session tokens and authentication cookies alongside passwords.
Aggregation Is The Harm, Again
This desk made the argument at 26-0615 for a 24-billion-record store: the individual thefts had already happened, and what changes is queryability. Credentials scattered across dozens of traded log sets are a nuisance; the same credentials in one indexed store are a capability.
This file is the earlier and larger instance of the same phenomenon, and the two together suggest aggregation is now a routine step in the infostealer economy rather than an occasional event.
The Session Tokens Matter More Than The Passwords
Where reporting indicates live session tokens and cookies were included, password rotation does not address the exposure. A replayed session presents no credential, consults no second factor, and appears as the legitimate user continuing.
That is why the practical advice attached to events like this — change your passwords — is necessary and insufficient, and why session invalidation on credential change is the control that actually closes the gap.
Graded medium, and the figure itself is contested. See 25-0626.
Compiled from public reporting, listed below. The 16 billion figure originates with the researchers who identified the datasets and is disputed; see the companion file. We did not access any data. Corrections: corrections@forensicpost.com.