A massive, unprotected database containing 149 million unique login credentials has been discovered by a digital security researcher. The exposure, which did not have any type of encryption or password, left the data vulnerable to anyone with access to its internet address. The volume of information poses a significant risk to millions of users around the world.
Within the vast dataset, a total of 48 million records corresponded to accounts from Gmail, Google’s popular email service. Além from the Google service, credentials were found for several other digital platforms, including social networks and streaming services, expanding the scope of the incident.
The initial investigation indicates that the information was not obtained through a direct invasion of the servers of the affected companies. Instead, the data was compiled over time by “infostealer” malware, which infects personal computers and steals information entered by users themselves.
The origin of the massive data compilation
Analysis of the files revealed that the database was continuously fed by logs generated by malware specialized in information theft. Esses Malicious programs operate silently on infected devices, capturing everything typed in login fields, such as usernames and passwords, as well as session cookies that can allow access to accounts without the need for credentials. Todo The collected material is then sent to remote servers controlled by cybercriminals, who aggregate it into large compilations for sale or use in future attacks. Curiosamente, the public exposure of this database, which totaled almost 100 GB, highlights a security flaw in the criminals’ own infrastructure, who left their repository of stolen data publicly accessible on the internet, allowing it to be identified and subsequently removed after notifying the hosting provider.
On the same topic: Data from 183 million Gmail and Outlook accounts exposed in new massive password leak
Technology giants in the crosshairs of criminals
Analysis of the distribution of exposed credentials shows a clear concentration on platforms with great global popularity. Gmail tops the list with approximately 48 million compromised accounts, followed by Facebook, with 17 million logins, and Instagram, with 6.5 million records.
Other notable services were also impacted, including Yahoo with 4 million accesses leaked, Netflix with 3.4 million credentials, and Outlook from Microsoft with 1.5 million entries. The diversity of targets shows the breadth of the data collection operation.
Learn more: Learn how to recover passwords saved on Google: a complete step-by-step guide for Android and iPhone phones
The severity of the incident is amplified by the presence of credentials to access government services from different countries and educational institution platforms. Isso elevates the risk beyond ordinary users and can affect the security of sensitive corporate and government data.
What is credential stuffing attack
With such a large volume of valid credentials in their possession, cybercriminals often resort to an automated attack technique known as “credential stuffing.” Nesse method, robots are programmed to systematically test leaked username and password combinations on a wide range of other websites and online services. The effectiveness of this tactic lies in the common habit of many users of reusing the same password across multiple platforms. A single compromised credential can thus serve as a master key to unlock access to numerous other accounts, from social networks to banking and e-commerce services.
The consequences for victims can be severe, ranging from the hijacking of profiles on social networks to direct financial losses and identity theft. Once criminals gain access to a primary email account, such as Gmail, they can use it to reset passwords for other associated services, deepening their control over an individual’s digital life. The scale of the attack is enhanced by automation, allowing millions of login attempts to be made in a short period of time, making detection and blocking a constant challenge for digital platforms.
Google’s response to the incident
In response to the discovery, Google stated that it constantly monitors external activity that could compromise its users’ accounts. The company highlighted that its security systems were not breached and that the exposed data is not the result of an internal failure.
More on this story: Vast amount of email credentials, including Gmail and Outlook, compromised by infostealers
The company reinforced that it has automated protection mechanisms that identify suspicious login activities. Quando a credential present in lists of known leaks is used, the system can block access and notify the user to immediately change the password, mitigating the risk of unauthorized access.
How infostealer malware spreads
Infostealer malware is designed to be discreet and efficient, installing itself on computers and mobile devices without the user noticing. The main route of infection remains social engineering, where the victim is tricked into carrying out a malicious action.
One of the most common tactics is sending phishing emails that contain infected attachments or links that point to fake websites. Esses websites often imitate legitimate login pages to directly steal credentials or trick malware into downloading.
Another significant vector of propagation is the download of pirated or “cracked” software from untrustworthy sources. Esses programs often come with embedded malware that is installed alongside the desired software, opening a gateway for criminals.
Once active on the system, these malicious programs operate in the background, recording data and sending it to their operators. Sua Increasing sophistication allows many of them to bypass basic antivirus software, making prevention and detection even more challenging for the average user.
Learn more: Sophisticated scam targets X users with emails that simulate login notifications
Essential recommendations for immediate protection
Faced with a large-scale exposure scenario, it is essential that users take proactive measures to protect their accounts. The first recommended action is to check whether your email addresses are on known leak lists, using specialized and reliable online tools for this query.
If compromise is suspected or confirmed, passwords for all accounts associated with the exposed email must be changed immediately. It is crucial to create unique and complex passwords for each service, avoiding reuse that facilitates credential stuffing attacks. Using a password manager is a highly recommended practice for creating and storing these credentials securely.
The extra layer of multi-factor authentication
The most effective security measure to protect against misuse of leaked passwords is to enable two-factor authentication (2FA) or multi-factor authentication (MFA) on all accounts that offer the feature. Essa functionality adds an extra layer of verification, requiring not only the password but also a second code, usually sent to a trusted device such as a cell phone. Mesmo Once a criminal has access to the password, he will not be able to complete the login without this second form of authentication, making the account significantly more secure against intrusion.

