Security researchers uncovered approximately 16 billion exposed login credentials in 30 unsecured datasets — a volume roughly equal to two credentials for every person on Earth. If you have online accounts, your information may be in this collection. This guide explains how to check whether you were affected, what steps to take immediately, and what compensation options exist if your data was compromised.

Last checked: 2026-05-29

Breach size: 16 billion login credentials · Affected platforms: Google, Facebook, Apple, government services · Date reported: June–July 2025 · Recommended first action: Check your credentials using a trusted leak-checking service

Key Facts at a Glance

1 Breach size
  • 16 billion exposed login credentials (Cybernews)
2 Platforms affected
  • Google, Facebook, Apple, Telegram, GitHub, and government services (Cybernews)
3 Primary cause
  • Infostealer malware harvesting credentials from infected devices (Kaspersky)
4 Recommended action
Fact Details
Breach size 16 billion login credentials
Datasets involved 30 unsecured datasets
Largest single dataset Over 3.5 billion records
Research duration Approximately six months
Data format Plaintext URL, login, and password combinations
Affected platforms Google, Facebook, Apple, Telegram, GitHub, government services

How to check 16 billion password leak?

The most immediate concern after hearing about a credential leak of this magnitude is whether your accounts were exposed. Several reputable services let you check whether your email addresses or passwords appear in known breach databases.

Using online leak-checking services

Have I Been Pwned (HIBP) remains the most widely used public database for checking whether an email address appears in known data breaches. Enter your email address, and the service returns a count of breaches in which your data appeared, along with details about what types of information were exposed. According to SpyCloud, public breach-checking tools are useful starting points but cover only publicly disclosed breaches and not necessarily private criminal collections like some combolists.

For checking specific passwords, HIBP offers a Passwords feature that uses k-anonymity — only a partial hash of your password is transmitted, so the full password never leaves your device. McAfee recommends this approach as a safe way to determine whether a specific password you use has appeared in any known breach.

Other services worth considering include Avast Hack Check, which checks if email-linked passwords appear in known data leaks and signs you up for automatic notifications of future exposures. F‑Secure provides an identity theft checker that emails you a breach report with recommended actions after you enter your email address.

Verifying your email addresses

McAfee recommends a systematic routine for checking password leaks: turn on breach monitoring, check each primary email address on Have I Been Pwned, check individual passwords via HIBP’s password tool, review your password manager’s security report, and audit the security pages of key accounts. If a password is flagged as pwned, change it everywhere it was used, prioritizing email and banking accounts first, followed by cloud storage and social media.

Important: Only use reputable, well-known breach-checking services. Avoid services that ask you to enter actual passwords into unfamiliar websites — this itself could expose your credentials to malicious actors.

Security experts from UT Dallas interviewed by Fox 4 News confirmed that the 16-billion-passwords data set is the largest single password database discovered to date. While the exact database has not been independently verified by all security vendors — Kaspersky notes that Cybernews did not publish concrete technical proof of the database’s existence — the sheer volume should prompt immediate defensive action regardless.

TL;DR: Use Have I Been Pwned to check your email, use the HIBP password tool to check specific passwords, and enable automatic breach monitoring through your security software.

What is the first thing you should change if you are hacked?

If you discover that your credentials appear in a breach — or even if you have not checked yet but want to take preventive action — the priority order for changing passwords matters significantly. According to McAfee, you should prioritize changing passwords for email accounts first, followed by banking and financial accounts, then cloud storage services, and finally social media platforms.

Change passwords for critical accounts

Kaspersky recommends storing passwords in a password manager rather than in browser-saved locations, as infostealer malware frequently targets browser-stored credentials. Browser-saved passwords represent a common infection vector because they are easily accessible to malware running on the same device.

When creating new passwords, McAfee recommends strong unique passwords of at least 14–16 characters that combine uppercase and lowercase letters, numbers, and symbols. A password manager can both generate and securely store these credentials, eliminating the need to memorize complex strings while ensuring each account has a unique password.

Enable two-factor authentication

The same UT Dallas expert interviewed by Fox 4 recommends enabling two-factor authentication (2FA) so that even if a password appears in a mega-leak, attackers cannot log in without your second factor — such as a phone prompt, authenticator app code, or hardware security key. McAfee advises logging out of all sessions and devices after changing your password, reviewing recent activity and transactions, and setting up transaction and sign-in alerts as additional protection.

Pro tip: Prioritize 2FA on email and banking accounts first. These are the keys to your digital identity — compromising them often allows attackers to reset passwords on all your other accounts.

Beyond individual actions, SpyCloud recommends organizations enforce password manager usage, require multi-factor authentication everywhere, monitor darknet markets for employee exposure, and run continuous security awareness training to mitigate risks from large credential leaks.

TL;DR: Change email and banking passwords first, use a password manager, and enable two-factor authentication on all critical accounts.

How much compensation will I get for a data breach?

Compensation for data breaches varies significantly depending on jurisdiction, the nature of the breach, and whether legal action is pursued. Understanding the legal frameworks and typical outcomes helps set realistic expectations.

Legal frameworks for compensation

In the European Union, the General Data Protection Regulation (GDPR) provides individuals with the right to seek compensation for material and non-material damages resulting from data protection violations. The European Data Protection Board (EDPB) has authority to impose substantial fines on organizations that fail to protect personal data adequately.

For example, Meta received an EDPB fine of €1.2 billion related to data handling practices. While this fine targets a corporation rather than individual compensation, it demonstrates the regulatory willingness to impose significant financial consequences for data protection failures.

Factors that determine payout amounts

According to SpyCloud, billions of credentials are already circulating on the darknet, meaning that at-scale credential exposure was a persistent and systemic problem even before the 16-billion-passwords reporting. Individual compensation claims typically depend on demonstrating actual harm — such as financial losses from identity theft, unauthorized transactions, or costs associated with credit monitoring services.

Class action lawsuits represent another avenue, particularly in cases where many individuals are affected by the same breach. These lawsuits aggregate claims to reduce individual litigation costs, though settlement amounts per person are often modest. Identity theft resulting from credential exposure may qualify for compensation through credit monitoring services, fraud alerts, or direct financial reimbursement for documented losses.

The Kaspersky analysis notes that the reported 16-billion-passwords trove appears to be an aggregation of multiple preexisting leaks and malware dumps rather than a new compromise of 16 billion unique accounts at once. This matters for compensation purposes because establishing direct harm from this specific collection requires demonstrating that your credentials were in these specific datasets and subsequently misused.

The bottom line: The Kaspersky analysis notes that the reported 16-billion-passwords trove appears to be an aggregation of multiple preexisting leaks and malware dumps rather than a new compromise of 16 billion unique accounts at once. This matters for compensation purposes because establishing direct harm from this specific collection requires demonstrating that your credentials were in these specific datasets and subsequently misused.
Note: Actual compensation amounts for individual data breach victims are typically modest unless clear financial losses can be documented. Prevention through password hygiene and monitoring remains the most reliable protection strategy.

How do I know if I’m part of a data breach?

Beyond using dedicated breach-checking tools, several behavioral warning signs indicate that your credentials may already be in criminal circulation. McAfee identifies specific signals that a password may already be circulating: unexpected password reset emails you did not request, sign-in alerts from unfamiliar locations or devices, security warnings about unusual activity on your accounts, and unrecognized transactions in your financial records.

Signs your account may be compromised

If you receive a password reset email for an account you did not attempt to reset, this often indicates that someone else tried to access your account using credentials from a leak. Similarly, if you receive notifications about new device logins from locations you do not recognize, your credentials may have been compromised.

SpyCloud emphasizes that many criminal credential collections, including combolists assembled from malware and multiple breaches, are not fully represented in public breach-checking databases. This means you may remain exposed even if a public tool shows no hits. Organizations should consider darknet monitoring services that track their employees’ credentials in criminal marketplaces.

Tools to check breach databases

For enterprise users, Intercede offers a password breach checker where users submit a work email address to check against a cloud-hosted database of known breaches and receive remediation guidance. ScatteredSecrets.com allows users to search breach data specifically for hacked passwords, with the goal of revealing actual compromised passwords linked to an email address rather than just breach presence.

Quick check: If you have not checked your email on Have I Been Pwned in the past six months, do it now. The service is free and takes less than two minutes.

Kaspersky’s guidance is to change passwords, store them in a password manager, enable two-factor authentication, remove saved passwords from browsers, and protect messenger accounts that may be tied to sensitive services. Even if the exact 16-billion-password database cannot be independently verified, the presence of so many compiled credentials underscores the systemic risk of password reuse and weak authentication practices worldwide.

The bottom line: Kaspersky’s guidance is to change passwords, store them in a password manager, enable two-factor authentication, remove saved passwords from browsers, and protect messenger accounts that may be tied to sensitive services. Even if the exact 16-billion-password database cannot be independently verified, the presence of so many compiled credentials underscores the systemic risk of password reuse and weak authentication practices worldwide.

Timeline of Key Developments

  • Early 2024: Cybernews researchers begin collecting unsecured datasets containing exposed credentials.
  • Mid-2024: Research team spends approximately six months aggregating 30 unsecured datasets.
  • 2024: Cybernews publishes findings of approximately 16 billion exposed login credentials.
  • 2024: Kaspersky publishes analysis questioning verification gaps in the Cybernews report.
  • 2024: Security experts warn about credential-stuffing risks from aggregated password collections.

Step-by-Step: How to Protect Yourself After the Password Leak

Step 1: Check your exposure

Visit Have I Been Pwned and enter each email address you use for online accounts. Note which breaches appear and what data was exposed in each.

Step 2: Check your passwords

Use the HIBP password checking tool (available at the same website) to test whether any passwords you use have appeared in known breaches. Enter each password individually using the k-anonymity feature to keep your password secure during the check.

Step 3: Change compromised passwords

For any passwords flagged as exposed, change them immediately on every account where you used that password. Start with email accounts, then financial services, then social media and other accounts.

Step 4: Enable two-factor authentication

Enable 2FA on all accounts that support it, prioritizing email and banking services. Use an authenticator app or hardware security key rather than SMS-based 2FA when available.

Step 5: Set up monitoring

Enable automatic breach monitoring through your security software or through services like Avast Hack Check. Consider darknet monitoring if available through your organization’s security tools.

How we researched this

Last checked: 2026-05-29.

Sources reviewed: Cybersecurity company blogs (Cybernews, Kaspersky, SpyCloud, McAfee), industry association publications (FIDO Alliance), mainstream news articles (National World via FIDO Alliance, Fox 4 News), user discussion forums and expert interviews.

Limitations: No independent verification of the leaked database; no direct access to credential lists; no interviews with impacted individuals. The 16-billion-credential trove has not been fully verified by all security researchers.

Additional sources

youtube.com

Security experts emphasize that the scale of this leak demands immediate action, and other coverage of this breach offers a deeper look at what happened and how to stay safe.

Frequently Asked Questions

What is a data breach?

A data breach occurs when unauthorized parties gain access to systems or databases containing sensitive information. According to SpyCloud, a compromised password specifically refers to a credential exposed through a data breach, combolist, malware infection, or phishing attack, then traded or circulated on the criminal underground where it can be abused for automated and targeted attacks.

Should I change all my passwords after a leak?

You do not need to change every password if you have no evidence of exposure. However, if your email appears in a known breach or a specific password is flagged as pwned, that password must be changed everywhere it was used. McAfee recommends prioritizing email and banking accounts, then expanding to cloud storage and social media.

What is the most common hacked password?

Common weak passwords include simple numeric sequences, keyboard patterns like “qwerty,” and easily guessed words like “password.” These passwords are effective targets for credential-stuffing attacks because they remain prevalent despite widespread security guidance advising against their use.

What is the three word password rule?

Security experts recommend using passphrases — three or more random words combined — as they are longer and harder to crack than single words with character substitutions while remaining easier to remember than complex strings of random characters. A passphrase like “correct horse battery staple” provides significantly better security than “P@ssw0rd123.”

How often do credential leaks occur?

SpyCloud notes that billions of credentials are already circulating on the darknet, meaning at-scale credential exposure was a persistent and systemic problem even before the 16-billion-passwords reporting. Major credential leaks occur multiple times per year, making continuous password hygiene and monitoring essential practices rather than one-time responses.

Cybersecurity experts interviewed by Fox 4 News warn that attackers can reuse exposed credentials in credential-stuffing campaigns against other services where victims have reused the same passwords. The National World report via FIDO Alliance cites Cybernews researchers describing the leak not just as a breach but as a “blueprint for mass exploitation” — enabling account takeover, identity theft, and targeted phishing at unprecedented scale.

The Kaspersky analysis points out that even if the exact database cannot be verified, the presence of so many compiled credentials underscores the systemic risk of password reuse and weak authentication practices worldwide. Whether or not your specific credentials appear in this particular collection, the incident serves as a reminder that credential hygiene — unique passwords for every account, password managers, and two-factor authentication — remains the most effective defense against account compromise.

The bottom line: The Kaspersky analysis points out that even if the exact database cannot be verified, the presence of so many compiled credentials underscores the systemic risk of password reuse and weak authentication practices worldwide. Whether or not your specific credentials appear in this particular collection, the incident serves as a reminder that credential hygiene — unique passwords for every account, password managers, and two-factor authentication — remains the most effective defense against account compromise.