Close Menu
Technology Mag

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot
    Asus’ new open earbuds are a wonderful companion for handheld gaming

    Asus’ new open earbuds are a wonderful companion for handheld gaming

    March 14, 2026
    Samsung Galaxy S26 Ultra review: show off

    Samsung Galaxy S26 Ultra review: show off

    March 14, 2026
    The Big 12 basketball tournament is ditching slippery LED courts for hardwood

    The Big 12 basketball tournament is ditching slippery LED courts for hardwood

    March 13, 2026
    Facebook X (Twitter) Instagram
    Subscribe
    Technology Mag
    Facebook X (Twitter) Instagram YouTube
    • Home
    • News
    • Business
    • Games
    • Gear
    • Reviews
    • Science
    • Security
    • Trending
    • Press Release
    Technology Mag
    Home » Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials
    Security

    Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials

    News RoomBy News RoomMay 24, 20253 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    Mysterious Database of 184 Million Records Exposes Vast Array of Login Credentials

    The possibility that data could be inadvertently exposed in a misconfigured or otherwise unsecured database is a longtime privacy nightmare that has been difficult to fully address. But the new discovery of a massive trove of 184 million records—including Apple, Facebook, and Google logins and credentials for accounts connected to multiple governments—underscores the risks of recklessly compiling sensitive information in a repository that could become a single point of failure.

    In early May, longtime data-breach hunter and security researcher Jeremiah Fowler discovered an exposed Elastic database containing 184,162,718 records across more than 47 GB of data. Typically, Fowler says, he is able to gather clues about who controls an exposed database from its contents—details about the organization, data related to its customers or employees, or other indicators that suggest why the data is being collected. This database, however, didn’t include any clues about who owns the data or where it may have been gathered from.

    The sheer range and massive scope of the login details, which include accounts connected to a large array of digital services, indicate that the data is some sort of compilation, possibly kept by researchers investigating a data breach or other cybercriminal activity or owned directly by attackers and stolen by infostealer malware.

    “This is probably one of the weirdest ones I’ve found in many years,” Fowler says. “As far as the risk factor here, this is way bigger than most of the stuff I find, because this is direct access into individual accounts. This is a cybercriminal’s dream working list.”

    Each record included an ID tag for the type of account, a URL for each website or service, and then usernames and plaintext passwords. Fowler notes that the password field was called “Senha,” the Portuguese word for password.

    In a sample of 10,000 records analyzed by Fowler, there were 479 Facebook accounts, 475 Google accounts, 240 Instagram accounts, 227 Roblox accounts, 209 Discord accounts, and more than 100 each of Microsoft, Netflix, and PayPal accounts. That sample—just a tiny fraction of the total exposure—also included Amazon, Apple, Nintendo, Snapchat, Spotify, Twitter, WordPress, and Yahoo logins, among many others. A keyword search of the sample by Fowler returned 187 instances of the word “bank” and 57 of “wallet.”

    Fowler, who did not download the data, says he contacted a sample of the exposed email addresses and heard back from some that they were genuine accounts.

    Aside from individuals, the exposed data also presented potential national security risks, Fowler says. In the 10,000 sample records there were 220 email addresses with .gov domains. These were linked to at least 29 countries, including the United States, Australia, Canada, China, India, Israel, New Zealand, Saudi Arabia, and the United Kingdom.

    While Fowler could not identify who had put the database together or where the login details originally came from, he reported the data exposure to World Host Group, the hosting company it was linked to. Access to the database was quickly shut down, Fowler says, although World Host Group did not respond to the researcher until after it was contacted by WIRED.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleBougeRV water heater review: hot showers to go
    Next Article The WIRED Travel Tech Guide to Family Vacation Harmony

    Related Posts

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    Cloudflare Has Blocked 416 Billion AI Bot Requests Since July 1

    December 6, 2025
    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    The Louisiana Department of Wildlife and Fisheries Is Detaining People for ICE

    December 5, 2025
    Your Data Might Determine How Much You Pay for Eggs

    Your Data Might Determine How Much You Pay for Eggs

    December 4, 2025
    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    Russia Wants This Mega Missile to Intimidate the West, but It Keeps Crashing

    December 4, 2025
    This Hacker Conference Installed a Literal Antivirus Monitoring System

    This Hacker Conference Installed a Literal Antivirus Monitoring System

    December 4, 2025
    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    Flock Uses Overseas Gig Workers to Build Its Surveillance AI

    December 4, 2025
    Our Picks
    Samsung Galaxy S26 Ultra review: show off

    Samsung Galaxy S26 Ultra review: show off

    March 14, 2026
    The Big 12 basketball tournament is ditching slippery LED courts for hardwood

    The Big 12 basketball tournament is ditching slippery LED courts for hardwood

    March 13, 2026
    Adobe will pay  million to settle US cancellation fee lawsuit

    Adobe will pay $75 million to settle US cancellation fee lawsuit

    March 13, 2026
    Digg’s open beta shuts down after just two months, blaming AI bot spam

    Digg’s open beta shuts down after just two months, blaming AI bot spam

    March 13, 2026
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss
    Trump Mobile is just one in the crowd of conservative carriers News

    Trump Mobile is just one in the crowd of conservative carriers

    By News RoomMarch 13, 2026

    Where’s the Trump phone? We’re going to keep talking about it every week. This week,…

    Microsoft’s Copilot AI assistant is coming to current-gen Xbox consoles this year

    Microsoft’s Copilot AI assistant is coming to current-gen Xbox consoles this year

    March 13, 2026
    Instagram is getting rid of end-to-end encrypted DMs that ‘very few’ people used

    Instagram is getting rid of end-to-end encrypted DMs that ‘very few’ people used

    March 13, 2026
    Google Pixel 10A review: Just buy the 9A

    Google Pixel 10A review: Just buy the 9A

    March 13, 2026
    Facebook X (Twitter) Instagram Pinterest
    • Privacy Policy
    • Terms of use
    • Advertise
    • Contact
    © 2026 Technology Mag. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.