In what is believed to be the largest data leak ever discovered, a staggering 26 billion records were exposed. The colossal leak consists of meticulously compiled and reindexed records from various data breaches and privately sold databases.
The discovery was spearheaded by Bob Dyachenko, a cybersecurity researcher and owner of SecurityDiscovery.com, along with help from the team at Cybernews. The researchers express deep concerns about the dataset’s potential misuse.
The researchers believe that the owner of the exposed dataset may be a malicious actor, a data broker, or a service dealing with substantial amounts of data. They also say that whoever it is is likely never to be uncovered.
The volume of data makes it somewhat of a goldmine for threat actors who could want to exploit it in any number of phishing schemes and cyberattacks. With many individuals reusing usernames and passwords across various platforms, perhaps the biggest threat from the pilfered data is a tsunami of credential-stuffing attacks
“In light of this, organizations must recognize the urgency of implementing comprehensive data protection strategies to mitigate the fallout from such breaches,” said Erfan Shadabi, cybersecurity expert at comforte AG.
The collection of breached data is believed to be the largest complication of multiple breaches to date, with a wealth of information beyond just login credentials.
A detailed examination of the data tree reveals an alarming array of records from previous breaches, with the largest chunk (1.4 billion records) originating from Tencent QQ, a Chinese instant messaging app. The extensive list also includes records from Weibo (504m), MySpace (360m), Twitter (281m), Deezer (258m), LinkedIn (251m), AdultFriendFinder (220m), Adobe (153m), Canva (143m), VK (101m), Daily Motion (86m), Dropbox (69m), Telegram (41m), and numerous other companies and organisations.
Recommended reading
- Which Data Breaches Had Everyone Talking This Year?
- 23andMe Says Breach Victims Are to Blame, Legal Action is Futile
- Report: Over Half of Data Breaches at UK Legal Firms Caused by Insiders
Government organisations in the US, Brazil, Germany, the Philippines, Turkey, and several other countries also find themselves part of this unprecedented data leak. The cybersecurity community is now grappling with the fallout as efforts are underway to contain the potential threats arising from this monumental breach.
“Most of us have some portion of our private information out on the Internet available to anyone. It’s a sad fact of life and I wonder how it impacts younger people and society overall to grow up in a world where our private information is no longer private,” said Roger Grimes, data-driven defense evangelist at KnowBe4.
“I think you have one side that just accepts that’s the way the world works now. The extreme opposite side is aggressively working to remove all their information from vendors and the Internet as best they can to go “off grid.” The MOAB database is just another datapoint supporting either group.”





