EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2025-16-billion-credentials-leak
062/430

File EL-0369CriticalOngoingData Breach / Credential Leak / Data Dump

16 Billion Credentials Mega Leak

Also filed as Largest Credential Dump 2025 · Google Apple Facebook Password Leak

One of the largest credential leaks in history, exposing over 16 billion user credentials and passwords compiled from major platforms including Google, Apple, and Facebook.

  • #credentials
  • #passwords
  • #pii
  • #mass-leak
Notoriety9/10
Event
1 Jun 2025
Disclosed
1 Jun 2025
Target
Multiple (Google, Apple, Facebook, others)
Scale
16.0B people
Status
Ongoing

01Summary

In June 2025, a massive compilation of 16 billion login credentials and passwords was leaked publicly. The dataset included reused and compromised accounts across major services, enabling widespread credential-stuffing attacks.

02Background

Credential reuse remains one of the biggest security risks. This compilation represented an unprecedented scale of exposed authentication data.

03Key revelations

  1. 01Scale of password reuse across major platforms.

04Technical analysis

The leak was a compilation of previously breached and stolen credentials aggregated into one massive dump, rather than a single new breach.

Attack vector
Credential compilation and public leak
Attack method
Data aggregation and distribution
Initial access
N/A (Compilation)

Vulnerabilities exploited

  • Password reuse

05Threat actor

Unknown compiler/distributor of aggregated breach data.

Attribution sources

  • Multiple security researchers
  • BleepingComputer
  • Guardz

06Victims and impact

Countries affected

  • Global

07Data exposed

Data types

  • Usernames
  • Passwords
  • Email addresses

08Financial damage

Massive increase in credential-stuffing attacks worldwide.

09Timeline

  1. 2025-06-01Massive credential dump surfaces.

10Reaction and fallout

Public reaction

Widespread panic and forced password resets across services.

Political impact

Increased calls for better passwordless authentication standards.

11Aftermath

Policy changes

  • Pushes toward passkeys and MFA adoption.

12Significance and legacy

Significance

Largest credential leak in recorded history.

Legacy

Accelerated global shift away from password-only authentication.

13Disclosure and media

Authentication
Public leak

Publishing organisations

  • Guardz
  • BleepingComputer

14Field notes

  1. 01Equivalent to roughly twice the world population in leaked records.

15Resolution

Data widely circulated; ongoing impact through credential stuffing.

16Sources

References

  1. [1]Guardz report
  2. [2]Security research publications
Fact sheetEL-0369

Dates

Event
1 Jun 2025
Started
1 Jun 2025
Discovered
1 Jun 2025
Disclosed
1 Jun 2025
Ongoing
Yes

Target

Organisation
Various major platforms
Type
Technology Companies
Sector
Technology
Country
Global

Actor

Motivation
Financial gain through sale and use in credential stuffing attacks.
Attribution
Low
Status
Active
Arrested
No
Convicted
No

Data

People
16,000,000,000
Records
16,000,000,000
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.