Unsecured Database Leak Reveals 184 Million Credentials from Major Online Platforms
A major data breach has been uncovered by cybersecurity researcher Jeremiah Fowler, who discovered an unprotected online database containing over 184 million account credentials. The exposed data included usernames, passwords, email addresses, and associated URLs, affecting major platforms like Google, Microsoft, Apple, Facebook, Instagram, and Snapchat. The credentials also covered financial, health, and government accounts, significantly raising the security stakes. The file was stored as a plain text document, without encryption or password protection, making it easy for malicious actors to access. Fowler believes the data was collected via infostealer malware, commonly used by cybercriminals to harvest login information for illegal use or sale on the dark web. While the hosting provider removed the file upon being notified, they declined to identify its owner, leaving the origin and intent behind the data collection unclear. Fowler contacted several people listed in the data, and many confirmed the accuracy of the credentials. He warned that users often store sensitive data in email accounts and reuse passwords, making them especially vulnerable. He recommends regular password changes, use of unique passwords via a manager, enabling multi-factor authentication, checking for leaked credentials, monitoring account activity, and maintaining up-to-date security software.
