---
title: "24 Billion Credential Leak Analysis | Firevault"
description: "Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak#webpage",
      "url": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak",
      "name": "24 Billion Credential Leak Analysis",
      "description": "Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "24 billion credentials exposed in record infostealer leak",
          "item": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "24 billion credentials exposed in record infostealer leak",
      "description": "Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.",
      "url": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-06-19T20:49:36.21902+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/24-billion-credentials-infostealer-leak"
      },
      "inLanguage": "en-GB",
      "articleSection": "Threat Analysis",
      "wordCount": 783,
      "keywords": "Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Cybernews researchers have uncovered an exposed Elasticsearch cluster holding roughly 24 billion records and more than 8.3 terabytes of data, drawn from infostealer malware logs, breach compilations and Telegram dumps. Even allowing for heavy duplication, it is one of the largest credential troves ever publicly catalogued. According to Deputy Editor Vilius Petkauskas, the team had to triple-check ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What was leaked?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "An exposed Elasticsearch cluster of about 8.3 TB containing roughly 24 billion records sourced from infostealer logs, breach compilations and Telegram dumps. Records include usernames, email addresses, plaintext passwords and the login URLs they belong to."
          }
        },
        {
          "@type": "Question",
          "name": "Am I affected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "It is safest to assume any password reused across personal and work accounts in the last several years is exposed. Rotate reused passwords, enable phishing-resistant multi-factor authentication such as passkeys or FIDO2 security keys, and monitor for infostealer indicators on your devices."
          }
        },
        {
          "@type": "Question",
          "name": "How does offline secure storage help?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Infostealers run on live, networked endpoints. A physically air-gapped Firevault module holds recovery keys, root credentials and succession material on hardware that the malware cannot reach, so a compromised laptop does not become a compromised vault."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What was foundWhy infostealer logs matterScale and the reuse problemThe Firevault viewWhat to do nowSourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Threat Analysis · 19 June 2026 

# 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2F24-billion-credentials-infostealer-leak)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2F24-billion-credentials-infostealer-leak&text=24%20billion%20credentials%20exposed%20in%20record%20infostealer%20leak%0A%0ACybernews%20researchers%20found%20an%208.3%20TB%20Elasticsearch%20cluster%20holding%2024%20billion%20records%2C%20including%20plaintext%20passwords%20and%20login%20URLs%20harvested%20from%20infostealer%20logs.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2F24-billion-credentials-infostealer-leak)[](mailto:?subject=24%20billion%20credentials%20exposed%20in%20record%20infostealer%20leak&body=Cybernews%20researchers%20found%20an%208.3%20TB%20Elasticsearch%20cluster%20holding%2024%20billion%20records%2C%20including%20plaintext%20passwords%20and%20login%20URLs%20harvested%20from%20infostealer%20logs.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2F24-billion-credentials-infostealer-leak)

![A heavy steel vault door slightly ajar, with reels of magnetic tape spilling out onto a concrete floor, lit by a low magenta accent glow.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg)

A heavy steel vault door slightly ajar, with reels of magnetic tape spilling out onto a concrete floor, lit by a low magenta accent glow.

Why it matters

## What this means for organisations holding critical data

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

In this analysis

1.  01 [What was found](#section-0)
2.  02 [Why infostealer logs matter](#section-1)
3.  03 [Scale and the reuse problem](#section-2)
4.  04 [The Firevault view](#section-3)
5.  05 [What to do now](#section-4)

**On this page**[What was found](#section-0)[Why infostealer logs matter](#section-1)[Scale and the reuse problem](#section-2)[The Firevault view](#section-3)[What to do now](#section-4)

Cybernews researchers have uncovered an exposed Elasticsearch cluster holding roughly 24 billion records and more than 8.3 terabytes of data, drawn from infostealer malware logs, breach compilations and Telegram dumps. Even allowing for heavy duplication, it is one of the largest credential troves ever publicly catalogued.

According to Deputy Editor Vilius Petkauskas, the team had to triple-check the find before publishing. The cluster pulled records from 36 separate sources, including breach "collections" and Telegram channels where stealer logs are routinely traded. The database is no longer publicly exposed, but the underlying credentials are already in circulation.

## What was found

The bulk of the records appear to be infostealer logs: structured captures lifted from infected endpoints by malware families such as RedLine, Raccoon and Lumma. A typical line contains a username, an email address, a plaintext password and the exact login URL the credential belongs to, sometimes with session cookies attached.

That format matters. Unlike a leaked password hash, an infostealer log is a working set of keys with the lock address printed on the front. Researchers cannot yet confirm how many records are duplicates, or how many unique people are affected, but the practical attack surface is enormous.

## Why infostealer logs matter

Infostealers do not guess passwords. They sit on a real device, wait for the user to log in, and copy what the browser already knows: saved credentials, autofill data, session cookies, crypto wallet files and, increasingly, multi-factor tokens. Strong password policies, rotation rules and SMS-based MFA do very little against that.

When those logs are aggregated into a single 24-billion-row index, two things happen at once. First, criminals can pivot from a low-value personal account to a corporate single sign-on entry point in minutes. Second, defenders lose any meaningful concept of "this credential is safe because it has not been in a public breach". The default assumption now has to be that it has.

## Scale and the reuse problem

Password reuse turns a personal credential leak into a corporate one. A laptop infected at home leaks the same password the user types into the company VPN. Pension, payroll and customer portals routinely show up in stealer logs alongside Netflix and Steam. With 24 billion records to draw on, credential-stuffing operators can saturate every public login endpoint at very low cost.

The financial services, e-commerce and SaaS sectors will absorb most of the visible damage. The harder problem is what happens to long-life secrets, the ones that protect recovery, succession and audit material. Those rarely rotate, and they are often stored in the same browser, password manager or cloud vault as everything else.

## The Firevault view

This is the failure mode Firevault was built to remove. A networked password manager, however well engineered, is reachable by anything that can run code on the endpoint. An infostealer that captures the master password, the session token or the cloud backup defeats the entire model in one step.

An [offline secure storage](/offline-secure-storage) module is not a replacement for a password manager. It is a physically separate place to hold the material that must survive an endpoint compromise: recovery keys, seed phrases, root credentials, succession instructions and the audit secrets you would need to rebuild trust afterwards. A Firebreak deployment keeps that material in a tamper-evident enclosure with no network path that a stealer log can ever reach.

The question we keep putting to security leaders is simple: if every credential your team has typed in the last five years showed up in a 24-billion-row index tomorrow, which of your secrets would you wish had never touched a browser?

## What to do now

-   Rotate any password that has been reused across personal and work accounts, starting with email, VPN, single sign-on and finance systems.
-   Move from SMS and app-based one-time codes to phishing-resistant multi-factor authentication: passkeys, FIDO2 security keys or platform authenticators.
-   Hunt for infostealer indicators on endpoints: unexpected browser profiles, recent password manager exports, anomalous traffic to Telegram or paste sites.
-   Move long-life secrets, recovery keys and succession material into an offline, physically air-gapped store. Talk to us about [gold-copy backups](/solutions/oss/use-cases/gold-copy-backups) and [Firebreak deployments](/firebreak).

## Sources

-   Vilius Petkauskas, Cybernews, ["24 billion records, including usernames and passwords, exposed in colossal data leak"](https://cybernews.com/security/24-billion-credentials-data-leak/).

_Analysis by Mark Fermor, Firevault._

**How Firevault helps**

-   **[Offline Secure Storage](/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
-   **[Control](/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.
-   **[Firebreak](/firebreak)** delivers hardware-enforced disconnection at Layer 1, so exposed credentials or compromised network paths cannot become a route into the vault.

_Talk to Firevault about [Disconnect to Protect®](/about) for your organisation._

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://cybernews.com/security/24-billion-credentials-data-leak/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg)

Threat Analysis 

### Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

22 Jun 2026 4 min 







](/news/scattered-spider-tfl-guilty-plea-offline-recovery)[

![UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg)

Threat Analysis 

### UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

20 Jun 2026 5 min 







](/news/ncsc-uk-critical-infrastructure-incidents-double)[

![FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials](/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg)

Threat Analysis 

### FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

18 Jun 2026 4 min 







](/news/fortibleed-74000-fortinet-firewalls-credentials-exposed)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)