THREAT LEVEL - HIGH

26-06-2025

16 Billion Credential Leak

Threat Level Description

IthacaLabs has maintained the Threat Level (High) adding a new observation:

An attack is highly likely. Addressing the broad nature of the threat in order to reach an acceptable risk level, requires additional and sustainable protective security measures combined with specific business and geographical vulnerabilities and judgments.

Description

Security researchers uncovered 30 separate datasets, totaling around 16 billion credentials including plaintext usernames, passwords and associated login URLs. These credentials include high profile platforms such as Apple, Facebook, Google, Telegram, GitHub. They also include VPNs, developer portals and government services.

The data appears fresh and not just historical dumps, implying recent infostealer malware activity. “Cybercriminals now have a blueprint for mass exploitation” as the researchers said. The researchers also warned “this is fresh, weaponizable intelligence at scale”. It is estimated that over two credentials per person on Earth were leaked, though the actual impact is unclear due to duplicate entries.

Exploitation Risk Scenarios:

  • Credential Stuffing
    • Automated use of leaked credentials to breach accounts is effective even with a less than 2% success rate, but at scale yields massive breaches.
  • Session Hijacking
    • Leaked tokens, cookies and metadata may bypass MFA protections.
  • Phishing and Social Engineering
    • Access to credential data enables credible targeted attacks.
  • Malware and Ransomware Campaigns
    • Compromised accounts can be pivot points into corporate environments.

Recommendation(s)

You should proceed immediately. Organization wide action is strongly advised:

  • Force immediate password resets across all critical systems and enforce strong, unique passwords via password managers.
  • Enable multi-factor authentication and consider passkeys where supported.
  • Analyze logs for unusual login attempts or failed logins, especially credential stuffing patterns.
  • Revoke and reissue session tokens, cookies and persistent logins.
  • Run threat hunts for signs of infostealer presence.
  • Communicate about phishing risks, suspicious links and the importance of updating passwords.
  • Audit MFA efficacy and consider rate limiting and blocker rules for failed login volumes.

You should understand the importance of security updates, and the urgency with which they should be applied, no matter how large or small your organization is. It is very important to apply an efficient patch management solution and always have enabled an active event security logging and practice event monitoring. To protect the valuable assets of your business and be compliant with the relevant industry regulations requires a comprehensive approach to the management of risk, including Penetration Testing at least annually and upon significant changes.

References:

SIGN UP

Get the latest Threat Alerts in your inbox.