惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Vercel News
Vercel News
博客园 - 【当耐特】
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
aimingoo的专栏
aimingoo的专栏
WordPress大学
WordPress大学
G
Google Developers Blog
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
P
Proofpoint News Feed
J
Java Code Geeks
U
Unit 42
云风的 BLOG
云风的 BLOG
阮一峰的网络日志
阮一峰的网络日志
N
Netflix TechBlog - Medium
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
Docker
V
Visual Studio Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
H
Help Net Security
V
V2EX
T
Tailwind CSS Blog

Gadget Review

Bernie Sanders Wants You to Own Half of OpenAI - And He's Not Kidding - Gadget Review California Bill Strikes Back Against Disappearing Video Games - Gadget Review Japan Cracks 6G's Speed Barrier With 112 Gbps Wireless Breakthrough - Gadget Review 31 Amazon Kitchen Tools and Gadgets That Make Prep Time a Breeze The 559-Mile Mic-Drop: Why BMW’s New i3 Just Made Tesla’s Range Look Like A Toy - Gadget Review 20 Genius Camping Gadgets That Will Help Make Summer Camping Easier Tesla Patents Transform Glass Roofs Into Smart Air Conditioners - Gadget Review Is Anthropic’s “Benefit Corp” Structure An Investor’s Worst Nightmare? - Gadget Review How An AI Weather Startup Just Beat the World’s Greatest Supercomputers - Gadget Review Dell's New XPS 13 Is Directly Targeting The MacBook Neo - Gadget Review 13 Smart Home Gadgets for True Local Control (No Cloud Needed!) Florida Sues OpenAI and CEO Sam Altman - Why Florida Is Treating AI Chatbots as "Hazardous Products" - Gadget Review Malaysia’s Scorched-Earth Policy Against Under-16 Social Media Access - Ban Carries Fines Up To $2.5 Million - Gadget Review PlayStation's Wireless Fight Stick and Latest Gaming Monitor Hits This August - Gadget Review How Meta's Chatbot Handed Over Million-Dollar Instagram Accounts To Attackers - Gadget Review 11 Home Security Gadgets That Help Safeguard Your Sanctuary Engineer Builds AI-Powered Laser System That Targets & Hunts Mosquitoes at Home - Gadget Review DuckDuckGo's No-AI Search Extensions Surge as Users Flee Google's AI Overhaul - Gadget Review Google Wants to Release 32 Million "Infected" Mosquitoes Into The Wild - Gadget Review Nvidia Is Bringing AI Power To Your Desk With New Superchip - Gadget Review Tech CEOs Are Using AI as the Perfect Scapegoat for Mass Layoffs - Gadget Review Wix Cuts 1,000 Jobs, Citing AI Evolution and Currency Pressures - Gadget Review Teen's Bluetooth Speaker Named "BOMB" Forces Flight U-Turn Mid-Atlantic - Gadget Review China's Humanoid Robots Sort 1,200 Postal Packages Per Hour - Gadget Review California Senate Passes Historic Ban on AI Chatbot Toys - Gadget Review Professor Declares War on AI: Will Fail Any Student Who Uses It - Gadget Review UK Military Looks At Allowing Lethal Strikes With Zero Human Intervention - Gadget Review Chinese EVs Are Tanking in Value - Gadget Review Japanese Researchers Create Chip That Could Run 1,000x Faster, Near-Zero Heat - Gadget Review Total Immobility: Why A Single Targeted Cyberattack Could Leave Every EV In Your City Stranded - Gadget Review
24 Billion Plaintext Passwords Exposed: What It Means for...
Al Landes · 2026-06-18 · via Gadget Review

Researchers found 8.3TB of login data across 36 sources left fully exposed, with no encryption or access controls

Twenty-four billion records. More than 8.3 terabytes of raw credential data. That’s what researchers at Cybernews reportedly found sitting in an exposed Elasticsearch database — no password protection, just an open door. This wasn’t a single company getting hacked. It was a compiled reservoir: usernames, email addresses, plaintext passwords, and login URLs pulled from infostealer malware logs, Telegram channels, and recycled breach data. Think of it less as a robbery and more as someone leaving a warehouse of stolen goods unlocked on a public street.

The database drew from 36 separate sources and appeared to be regularly updated — researchers found a February 2026 news item buried inside. Roughly 260 million records were tied to Telegram channels labeled “Darkside,” suggesting connections to ransomware-adjacent criminal networks, according to TechRadar.

The most unsettling detail? Every password was stored in plaintext. No hashing. No cracking required. Attackers could copy, paste, and go.

  • 24 billion records totaling over 8.3TB of data, according to Cybernews
  • Records included usernames, email addresses, plaintext passwords, and login URLs
  • Compiled from 36 sources including infostealer malware logs and Telegram channels
  • Approximately 260 million records linked to “Darkside”-labeled Telegram channels (TechRadar)
  • The database owner remains unknown; the cluster has since been taken offline

“The credential data leak is dangerous simply because of its enormous size,” according to Cybernews.

Your Accounts Are Only as Strong as Your Weakest Reused Password

Whether or not your credentials appear in this specific dataset, the way attackers exploit leaks like this one puts every reused password at serious risk.

Credential stuffing is straightforward and brutal: attackers take leaked passwords and spray them across other services until something opens. Cybernews warns that billions of accounts face serious takeover risk, particularly where users haven’t enabled multi-factor authentication. Nobody knows how many duplicates exist within the 24 billion records, so the number of uniquely affected individuals remains genuinely unclear — but that uncertainty doesn’t reduce your exposure if you reuse passwords.

Password reuse is the digital equivalent of using the same four-digit PIN for your phone, your bank, and your gym locker. One compromise unlocks everything. You can check whether your email address appears in known breach data at Have I Been Pwned (haveibeenpwned.com), a reputable, free tool maintained by security researcher Troy Hunt.

Enable MFA on every account that supports it. Use a unique password for each service. The database is offline now, but credential copies spread like leaked Spotify Wrapped screenshots — fast, wide, and permanently beyond anyone’s control.