Overview
- Have I Been Pwned added roughly 56.3 million unique email addresses and 124 million unique passwords from stealer‑logs to its searchable indexes in mid‑June.
- Independent researchers reported a separate, far larger unsecured collection of about 24 billion records on a server that combined 36 sources and whose operator remains unidentified.
- Infostealer malware harvests saved passwords, browser cookies, tokens and other data from infected devices and compiles 'stealer‑logs' that are traded or aggregated into huge databases.
- Security agencies and experts advise users to stop reusing passwords, enable multi‑factor authentication, use a password manager, and check exposure via services such as Have I Been Pwned.
- The new findings echo earlier mega‑collections and heighten the risk of widespread credential‑stuffing attacks, while investigations and monitoring of the datasets’ circulation continue.