Emma Carter, a 38-year-old primary school teacher from Leeds, UK, thought she was simply checking her emails during a break. Instead, she was locked out of her Gmail, her Amazon orders were rerouted, and £400 vanished from her bank account. “I had no idea how they got in,” she said. The answer? Her login credentials had been part of a massive data breach the largest ever recorded.
In June 2025, cybersecurity researchers at Cybernews revealed a staggering leak of over 16 billion login credentials, stolen from users of services including Apple, Google, Facebook, Telegram, GitHub, and even government portals. Spanning 30 distinct datasets, each containing tens of millions to billions of entries, this breach dwarfs the infamous 2024 RockYou2024 leak, which exposed 10 billion records.
“This is the most significant credential exposure we’ve ever seen,”
said Vilius Petkauskas, lead researcher at Cybernews.
This was not a hack of Apple or Google itself. Instead, the credentials were nabbed by infostealer malware malicious software that infects your device and quietly copies things like usernames, passwords, browser cookies, and even session tokens. This information was contained in unprotected cloud servers (read: online data lockers) that were inadvertently left open.
“These aren’t old or recycled passwords,”
warned Jeremiah Fowler, a cybersecurity expert who previously uncovered a May 2025 leak of 184 million credentials.
“These are fresh, active logins many still usable.”
The stolen data was later discovered scattered across unprotected databases one linked to Russia (455 million records) and another containing 60 million entries tied to Telegram users.
This hack is not a story about technology. It’s a wake-up call to all online shoppers, online bankers, and social networkers.
Cybercrooks now have billions of logins to employ in phishing attacks, identity thefts, account takeovers, and in a process known as credential stuffing (in which pilfered logins are automatically tried out on other sites).
Especially worrying: the leak contains logins for crypto wallets and government accounts, sparking fears of financial loss and national security risks.
“Think of it like leaving a digital safe unlocked,”
said Keeper Security.
“The keys to your entire online life are now in the wild.”
What You Can Do: 5 Quick Steps to Stay Safe
Opt for two-factor authentication (2FA) using an app, such as with Google Authenticator or by using a physical security key.
For every account, generate, and save strong, unique passwords via a password manager.
Stop reusing passwords. If you use the same password for Gmail and Facebook, change them now.
Check your exposure on trusted sites like Have I Been Pwned or Google’s Password Checkup tool.
Stay alert for phishing messages or suspicious login alerts.
While others such as Google have countered by advocating for passkey security (alternative forms of passwordless login), Facebook and Apple have so far made no overall public comments.
This isn’t just another news headline it’s a personal security crisis affecting millions of real people. Whether you’re a teacher in Leeds, a freelancer in Toronto, or a small business owner in Sydney, your digital life may have just been cracked wide open.
Take control now. Update your passwords, enable 2FA, and stay vigilant.
As Vilius Petkauskas put it,
“The threat is real, but so is your power to fight back.”

