§ Claim under review · Mixed
"24 billion usernames and passwords found sitting wide open on the internet. That's roughly 3 logins for every human alive... Researchers found an 8.3TB database left online with no password on it... Much of it in plaintext... Where did it come from? Mostly infostealer malware... Then it gets traded on Telegram like footy cards... nobody knows how many of the 24 billion are duplicates. It's not 24 billion separate people."
Verdict
Mostly accurate
Confidence
HighSummary
This claim is mostly accurate. Cybernews researchers reported finding an unsecured 8.3 TB Elasticsearch database containing about 24 billion credential records, largely sourced from infostealer malware logs and Telegram-distributed breach compilations, with much of it in plaintext. The post correctly notes that the number of duplicates is unknown and that 24 billion records does not equal 24 billion distinct people. A small simplification is that the 24 billion figure refers to records (which also include emails and login URLs), not strictly 24 billion unique username-password pairs. The practical advice in the post, checking Have I Been Pwned, changing reused passwords, and enabling two-factor authentication, is consistent with standard guidance for this kind of exposure.
The readings
key figures from the evidencecredential records found in exposed database
size of the exposed Elasticsearch cluster
sources the data was aggregated from
Why this verdict
Evidence
The Cybernews research team reports that they found an exposed Elasticsearch cluster containing 24 billion records and more than 8.3TB of data, with most records appearing to be infostealer logs, including usernames, emails, passwords, and login URLs . The data came from 36 sources, including Telegram channels, breach compilations, and large "collections."
Researchers cannot yet confirm how many records are duplicates or how many unique people were affected. Secondary reporting confirms the database was publicly reachable without authentication and has since been taken offline, with the data reportedly coming from 36 sources including numerous Telegram channels, prior breach compilations , and infostealer malware output.
Findings
✓ What's accurate 5
- A database of about 24 billion credential records and 8.3 TB was discovered exposed online without authentication.
- Much of the content was in plaintext, listing passwords alongside the associated login URLs.
- The data was largely sourced from infostealer malware and traded/aggregated via Telegram channels and breach compilations.
- The number of duplicates and unique victims is not known.
- The 24 billion figure is roughly three times the world's population, so "3 logins for every human alive" is a fair back-of-envelope ratio (not a claim that 3 accounts exist per person).
≈ What's misleading 2
- Minor framing: the post's phrasing "24 billion usernames and passwords" is slightly narrower than what researchers described. The dataset is 24 billion "records" that also include emails and URLs, not 24 billion distinct username-password pairs. This is a common simplification in secondary reporting and does not materially change the meaning, especially because the post itself later notes duplicates are unknown.
- "3 logins for every human alive" is a rhetorical ratio, not a per-person estimate. The post explicitly disclaims this, which mitigates the risk of misreading.
? What's uncertain 3
- The proportion of the 24 billion records that are duplicates versus unique credentials. Cybernews explicitly states this is not yet known.
- The exact number of unique individuals affected.
- Attribution: who compiled and hosted the database has not been publicly identified in the sources reviewed.
Sources
1 of 4 linked to recordsCybernews research report, "24 billion records, including usernames and passwords, exposed in colossal data leak"
Malwarebytes Labs coverage
TechRepublic coverage
TechTimes coverage