A publicly exposed Elasticsearch deployment reported in June 2026 held on the order of 24 billion credential records, described as infostealer logs aggregated from around 36 separate sources.
Almost nothing in that collection was new. Infostealer malware has been harvesting saved passwords, session cookies and autofill data from consumer machines for years, and the individual thefts had already happened, at scale, across many campaigns.
Aggregation Changes What The Data Can Do
Credentials scattered across dozens of separately traded log sets are a nuisance. The same credentials in one indexed store are a capability: you can query by domain, by email, by organisation, and get every credential ever harvested for a given target in a single result set.
That is the difference between raw material and a tool, and it is the reason we file exposures of aggregated data as their own category rather than as a footnote to the campaigns that produced them.
Rotation Is Not The Whole Answer
Password rotation addresses part of it. Session cookies are the harder half: a stolen session can be replayed without ever presenting a credential, which means a second factor is not consulted, and the activity looks like the legitimate user continuing a legitimate session.
The defence is session invalidation on credential change, binding sessions to device posture, and treating a token as something with a lifetime rather than a convenience — all of which cost users something, which is why they are frequently not done.
Compiled from public reporting, listed below. Record counts are as reported by the researchers who identified the exposure; we did not access the data. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense