Future Retirement Success
  • Politics
  • Business
  • Investing
  • Stocks
  • Politics
  • Business
  • Investing
  • Stocks

Future Retirement Success

Business

Internet users urged to change passwords after 16bn login credentials found online

by June 23, 2025
June 23, 2025
Internet users urged to change passwords after 16bn login credentials found online

Internet users are being urged to change their passwords and bolster their online security after cybersecurity researchers discovered 16 billion login credentials in publicly exposed datasets — a trove that could be used by criminals to hijack everything from social media accounts to email logins.

The revelation comes from researchers at Cybernews, who uncovered 30 separate datasets containing credentials gathered through malicious software known as “infostealers”, as well as from historic data breaches. While many of the records are likely duplicates or already in criminal circulation, the scale of the find is alarming and underscores the persistent vulnerability of personal data online.

The exposed credentials could, in theory, offer access to services including Facebook, Google, and Apple, though none of these companies suffered a new breach. Instead, the data was obtained from third-party sources — typically through malware infections on users’ devices that steal saved logins and passwords directly from browsers or password managers.

Bob Diachenko, a respected Ukrainian cybersecurity expert who led the research, said the records were briefly accessible after being misconfigured on remote servers before being taken down. “It will take some time to assess and contact those affected, because it’s an enormous amount of data,” he said.

Cybersecurity analysts have been quick to caution that this is not the result of a new major data breach, but rather a reflection of how dangerous and widely available previously stolen data remains. Much of the data stems from logs generated by infostealer malware, which can harvest login credentials, session cookies, browsing history, and even saved credit card information.

According to Diachenko, the vast majority of the exposed information — about 85% — appears to be from such infostealer logs, with the remainder coming from older breaches such as the 2012 LinkedIn hack.

The data troves followed a clear structure: URLs, followed by usernames and passwords. The potential for account takeovers, phishing attacks, and identity theft is significant, especially if users have reused passwords across multiple services.

Google, responding to the report, confirmed the leak did not originate from any Google systems, and encouraged users to secure their accounts using tools like Google Password Manager and passkeys, a newer password-free authentication method. Meta and Apple have yet to respond publicly.

Toby Lewis, global head of threat analysis at Darktrace, warned that infostealers remain “very much real and in use by bad actors.” While they don’t directly log into accounts, they “scrape information from browser cookies and metadata,” giving attackers a way around passwords altogether.

Peter Mackenzie, director at Sophos, emphasised that the news serves as a stark reminder of the depth of personal data available to cybercriminals. “There is no new threat here, but it shows how much sensitive information is still floating around. If you haven’t changed your passwords or enabled multifactor authentication, now’s the time.”

Experts recommend that anyone concerned should:
• Immediately change passwords, especially if reusing the same credentials across platforms.
• Enable multifactor authentication (MFA) wherever available, adding an extra layer of security.
• Use a password manager to generate and store unique, strong passwords.
• Check whether personal information has been compromised using services like HaveIBeenPwned.com.

Alan Woodward, professor of cybersecurity at the University of Surrey, called it a good time for “password spring cleaning.” He added: “The fact that everything seems to be breached eventually is why there’s such a strong push toward zero-trust security models, which don’t assume any device or user is inherently safe.”

Cybernews said that although the exposed datasets were quickly taken down and haven’t been widely circulated on public forums, they represent a “blueprint for mass exploitation” and warned that complacency could leave users vulnerable.

In an era where one compromised login can unlock access to emails, financial records, or private conversations, experts agree: staying proactive is no longer optional — it’s essential.

Read more:
Internet users urged to change passwords after 16bn login credentials found online

0
FacebookTwitterGoogle +Pinterest
previous post
OpenAI takes down Jony Ive’s ‘io’ content after trademark complaint from earbud startup iyO
next post
UK government unveils £275m boost to skills and apprenticeships to revive industrial heartlands

You may also like

Labour to Tackle Private Equity Tax Loophole in...

June 8, 2024

Half of UK SMEs have had loan application...

September 5, 2022

The Peter Jones Foundation and FRP join forces...

May 12, 2025

Tax-free shopping cut costs London’s West End £640m...

February 14, 2025

The Benefits of Hiring a Local Car Accident...

March 29, 2025

Experts predict that the US stock market will...

April 14, 2025

Tax breaks urged to recharge UK’s struggling electric...

April 20, 2023

Four in ten UK businesses nearly closed in...

September 17, 2024

Top 6 Strategies to Improve Your Business and...

May 30, 2023

Start-ups hit the brakes on hiring as costs...

August 15, 2022

    Get free access to all of the retirement secrets and income strategies from our experts! or Join The Exclusive Subscription Today And Get the Premium Articles Acess for Free

    By opting in you agree to receive emails from us and our affiliates. Your information is secure and your privacy is protected.

    Recent Posts

    • Election Policy Roundup

      June 23, 2025
    • Moderate House Dem Jared Golden says Trump was ‘right’ to strike Iran

      June 23, 2025
    • Iran attacks US base in Qatar, Trump thanks Tehran for advance notice and ‘very weak response’

      June 23, 2025
    • Hakeem Jeffries demands Trump ‘justify’ striking Iran, but side-steps impeachment question

      June 23, 2025
    • Ex-Clinton official applauds Trump’s ‘courageous’ Iran call, doubts Harris would’ve had the nerve

      June 23, 2025
    • Bush’s War on Terror vs Trump’s Iran approach: How US Middle East strategy evolved

      June 23, 2025

    Categories

    • Business (8,287)
    • Investing (2,063)
    • Politics (15,764)
    • Stocks (3,164)
    • About us
    • Privacy Policy
    • Terms & Conditions

    Disclaimer: futureretirementsuccess.com, its managers, its employees, and assigns (collectively “The Company”) do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

    Copyright © 2025 futureretirementsuccess.com | All Rights Reserved