One of the largest credential leaks in recent years recently came to light, causing great concern in the cybersecurity community. A massive database, measuring 96 GB in size, was found exposed online without any protection measures (e.g. password or encryption), containing nearly 149 million unique login details.
This exposure poses serious risks to users of popular services, such as Gmail, Facebook, Instagram, Netflix, and thousands of other platforms worldwide, as it provides cybercriminals with a ready-made "arsenal" for mass attacks.
What did the exposed database include?
According to available data, the database contained 149,404,754 unique sets of credentials that had been harvested through infostealers and keyloggers. Each record included email addresses, usernames, passwords , and – most worryingly – the exact URL links to log in to the respective accounts.
See also: Phishing: Installing LogMeIn for persistent access to systems

This means that an attacker does not need to guess or search for the correct login page, as all the necessary data is ready for automated attacks credential stuffing against unsuspecting users.
Analysis of exposed accounts
A limited sample of the data revealed some disheartening statistics. About 48 million Gmail accounts were reportedly exposed, along with 4 million Yahoo accounts, 1.5 million Outlook accounts , and nearly 900,000 iCloud accounts. Of particular concern is the presence of about 1.4 million .edu email addresses, which belong to educational institutions.
Social media platforms were not left untouched. The dataset shows 17 million Facebook credentials, 6.5 million Instagram accounts , and around 780,000 TikTok accounts.
Streaming, crypto and subscription platforms in the spotlight
Entertainment services were also hit hard , with 3.4 million Netflix accounts included in the database. At the same time, around 420,000 cryptocurrency accounts Binance were identified , raising fears of immediate financial losses.
See also: Telnet authentication bypass exposes devices to full takeover
Even platforms like OnlyFans appear on the list, with more than 100,000 credentials, impacting both content creators and subscribers.
Government domains and national security
Of particular concern is the presence of credentials associated with .gov domains from various countries. While not all government accounts provide access to sensitive systems, even limited access can be used for targeted attacks spear-phishing, impersonation , and infiltration of government networks.

Experts warn that such leaks can act as "entry points," with potential implications for public and national security.
How the stolen data was organized
The files contained structured metadata, formatted as “host_reversed path” (e.g. com.example.user.machine), allowing data to be organized by victim and source of infection. At the same time, unique hashes were used to avoid duplicate records, indicating that the database had been created in a professional and systematic manner.
Delayed response and unanswered questions
Cybersecurity researcher Jeremiah Fowler was the one who discovered the database and notified ExpressVPN as part of a broader investigation. Despite immediately reporting it to the hosting, the response was significantly delayed, with the database remaining publicly accessible for almost a month.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Vishing campaign targets Okta SSO accounts for data theft
Even more worrying is the fact that the number of files increased during this period, suggesting ongoing data collection. The provider refused to reveal the owner of the database, leaving crucial questions unanswered.

What users should do immediately
Experts recommend using up-to-date antivirus software, as surveys show that only 66% of adults in the US use such solutions. At the same time, two-factor authentication, password managers and regular account activity monitoring are now considered essential.
Those who suspect a device infection should immediately proceed with a full malware scan, system updates , and review of application and extension permissions, as in a landscape of ever-growing threats, prevention is the only reliable defense.
