Desk live·
ForensicPost
Cloud/Exposure/File 26-0615

Exposed Elasticsearch Instance Held 24 Billion Credential Records

A publicly exposed Elasticsearch instance held around 24 billion credential records aggregated from 36 infostealer sources. The aggregation is the harm; the individual thefts were already done.

Constructed geometry · not a chart of case data
TargetExposed Elasticsearch instance
ActorExposure
S. Rosler8 min readConfidence: medium1 source reviewed

A publicly exposed Elasticsearch deployment reported in June 2026 held on the order of 24 billion credential records, described as infostealer logs aggregated from around 36 separate sources.

Almost nothing in that collection was new. Infostealer malware has been harvesting saved passwords, session cookies and autofill data from consumer machines for years, and the individual thefts had already happened, at scale, across many campaigns.

Aggregation Changes What The Data Can Do

Credentials scattered across dozens of separately traded log sets are a nuisance. The same credentials in one indexed store are a capability: you can query by domain, by email, by organisation, and get every credential ever harvested for a given target in a single result set.

That is the difference between raw material and a tool, and it is the reason we file exposures of aggregated data as their own category rather than as a footnote to the campaigns that produced them.

Rotation Is Not The Whole Answer

Password rotation addresses part of it. Session cookies are the harder half: a stolen session can be replayed without ever presenting a credential, which means a second factor is not consulted, and the activity looks like the legitimate user continuing a legitimate session.

The defence is session invalidation on credential change, binding sessions to device posture, and treating a token as something with a lifetime rather than a convenience — all of which cost users something, which is why they are frequently not done.

How we reported this

Compiled from public reporting, listed below. Record counts are as reported by the researchers who identified the exposure; we did not access the data. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary