Desk live·
ForensicPost
Cloud/Exposure/File 25-0620

Sixteen Billion Credentials in Thirty Unsecured Datasets

Researchers reported 30 exposed datasets holding some 16 billion credential records in June 2025 — infostealer logs, credential-stuffing compilations and repackaged older leaks.

Constructed geometry · not a chart of case data
TargetExposed credential aggregates
ActorExposure
D. Kennedy11 min readConfidence: medium3 sources reviewed

In June 2025 researchers reported discovering 30 unsecured datasets containing approximately 16 billion credential records — described as the largest such exposure recorded. The records were structured by site, username and password, spanning consumer platforms, VPNs, developer portals and government services.

The material was characterised as a mixture of recent infostealer logs, credential-stuffing compilations and repackaged older breaches. Some reporting noted the inclusion of session tokens and authentication cookies alongside passwords.

Aggregation Is The Harm, Again

This desk made the argument at 26-0615 for a 24-billion-record store: the individual thefts had already happened, and what changes is queryability. Credentials scattered across dozens of traded log sets are a nuisance; the same credentials in one indexed store are a capability.

This file is the earlier and larger instance of the same phenomenon, and the two together suggest aggregation is now a routine step in the infostealer economy rather than an occasional event.

The Session Tokens Matter More Than The Passwords

Where reporting indicates live session tokens and cookies were included, password rotation does not address the exposure. A replayed session presents no credential, consults no second factor, and appears as the legitimate user continuing.

That is why the practical advice attached to events like this — change your passwords — is necessary and insufficient, and why session invalidation on credential change is the control that actually closes the gap.

Graded medium, and the figure itself is contested. See 25-0626.

How we reported this

Compiled from public reporting, listed below. The 16 billion figure originates with the researchers who identified the datasets and is disputed; see the companion file. We did not access any data. Corrections: corrections@forensicpost.com.

Sources
  1. 16 billion passwords exposed in record-breaking data breachCybernews
  2. The world’s largest credential leak hits 16 billion recordsBlackFog
  3. 16 billion credentials exposed: why this infostealer leak demands a rethinkF5
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary