London, 26 January 2026 — A vast trove of 149 million usernames and passwords from major online services was exposed in an unsecured database, cybersecurity experts have confirmed. The cache — including credentials for Gmail, Facebook and other platforms — was publicly accessible until recently and has now been taken offline after being reported to the hosting provider.
Security researcher Jeremiah Fowler discovered the unprotected database in late January. He found login information for a wide range of accounts, including 48 million Gmail logins, 17 million Facebook credentials, and around 420,000 linked to the cryptocurrency platform Binance. The database also contained details for Yahoo, Microsoft Outlook, Apple iCloud, academic (.edu) accounts and popular streaming services such as Netflix and TikTok.
How It Happened
Investigators believe the dataset was collected using infostealing malware — malicious software that silently harvests usernames and passwords from infected devices, often using techniques like keylogging. The information was then stored in a searchable format on the server, making it trivial to access without authentication.
Mr Fowler noted that the database continued to grow for nearly a month while he attempted to contact the hosting provider, which eventually took it down after finding it violated service terms. The identity of the database’s operator remains unknown.
Wide-Ranging Risks
Experts warn that exposed credentials like these pose serious risks. Stolen usernames and passwords are a key enabler for credential stuffing attacks — where attackers use automated tools to try stolen login pairs across multiple websites, taking advantage of password reuse.
With millions of accounts across social media, email, entertainment, financial and potentially government-related services affected, individuals and organisations could face heightened threats of identity theft, fraud and unauthorised access in the coming weeks.
Advice for Users
Security professionals urge users to:
- Change passwords immediately, especially on accounts using the same credentials across services.
- Enable multi-factor authentication (MFA) wherever possible.
- Use a password manager to create and store strong, unique passwords for every account.
- Monitor accounts for unusual activity and sign-in alerts.
The incident underlines both the ongoing threat posed by malware-driven credential harvesting and the importance of robust personal security practices in an increasingly interconnected online world.










