Huge data leak exposes 149 million credentials without protection

A massive data breach has come to light, involving 149 million credentials left exposed online. The 98GB cache includes unique usernames and passwords from financial services, social media, and dating apps. The discovery highlights ongoing vulnerabilities in digital security.

The enormous cache of data, totaling 98GB, was found without any protective measures, making it easily accessible to potential bad actors. This leak encompasses credentials from various sectors, including financial services where users manage banking and investments, social media platforms used for daily communication, and dating apps that handle personal information.

Details emerged on January 23, 2026, underscoring the scale of the exposure: 149 million unique usernames and passwords. No encryption or safeguards were in place, amplifying the risk of identity theft, account takeovers, and financial losses for affected individuals.

Experts in cybersecurity have long warned about the dangers of unencrypted data dumps, but this incident serves as a stark reminder of how quickly such information can surface online. Users are advised to monitor their accounts and update passwords, though the full impact remains unclear without further details on the breach's origin.

The event raises questions about data handling practices across these industries, potentially prompting regulatory scrutiny.

Relaterede artikler

Dramatic illustration of a darknet leak of Swedish government IT data by hackers, showing computer screens with source code, passwords, and personal files.
Billede genereret af AI

Swedish government IT data leaked on darknet

Rapporteret af AI Billede genereret af AI

A hacker group called ByteToBreach has leaked sensitive information from a government IT system on the darknet. The leak includes source code, passwords, and personal data from a platform managed by IT consultant CGI Sweden. Authorities like Cert-SE confirm they are aware of the reports but decline to comment.

Researchers analyzing 10 million web pages have identified 1,748 active API credentials from 14 major providers exposed across nearly 10,000 websites, including those run by banks and healthcare providers. These leaks could enable attackers to access sensitive data or gain control over digital infrastructure. Nurullah Demir of Stanford University described the issue as very significant, affecting even major companies.

Rapporteret af AI

Adult entertainment website Frivol has disclosed a data leak that may impact around 479,000 users. The breach involved an open database containing user details. The revelation was reported on February 25, 2026.

A TechRadar report states that over 29 million secrets were leaked on GitHub in 2025. The article suggests that AI is not helping and may be making the situation worse.

Rapporteret af AI

In 2026, organizations in Colombia face an average of 2,803 weekly cyberattacks, with potential losses up to US$6.3 million per incident. Recent data leaks via third-party providers have exposed sensitive information from BBVA and Nubank clients, as well as from entities like Supersalud and Dian. Experts warn about the vulnerability of these weak links in the security chain.

Dette websted bruger cookies

Vi bruger cookies til analyse for at forbedre vores side. Læs vores privatlivspolitik for mere information.
Afvis