149 Million Credentials Exposed Online-What This Massive Data Leak Means for You and Your Business
A massive 149 million usernames and passwords have been discovered exposed online, completely unprotected, without encryption, and publicly accessible to anyone! Cybersecurity researcher Jeremiah Fowler uncovered the database, which contained 98GB of login credentials from financial services, social media platforms, dating apps, streaming services, and more.
This wasn’t a breach of a single company—it's a giant collection of stolen usernames and passwords, most gathered through malware that quietly harvests credentials from infected devices.
The scale of this leak is huge:
- 48 million Gmail accounts
- 17 million Facebook accounts
- 6.5 million Instagram accounts
- 3.4 million Netflix accounts
As if that wasn't worrying enought, the data was indexed in a way that made it easily searchable—meaning cybercriminals organise the data and get the information they want quickly and easily. If that wasn't enough, this database sat open for almost a month before being taken down, with even more stolen credentials bring added during that time.
This is why we as IT people bang on about not using the same passwords on multiple sites. Your password to a really important business site is now out there, because you used the same password on Facebook. These passwords are currently being tried constantly by automated systems to access thousands of important websites and systems, it's only a matter of time. The argument "we're too small for them to bother with" doesn't apply, if you're on the list of leaked accounts, they'll try as it costs them nothing.
Why This Matters
This isn’t just another headline. When millions of passwords are leaked, attackers run credential‑stuffing attacks (trying the same password across mutliple services).
If users reuse passwords on multiple sites or work accounts, hackers can instantly access those accounts.
Financial, government, and business accounts become prime targets.
Even if one user in your company is compromised, attackers could pivot inside your systems.
What You Should Do Right Now
Currently at time of writing (24/01/2026), there is no notification that this leak has been absorbed by the leak checking site Have I Been Pwned. So there isn't an easy way of knowing if your details are included. If you're concerned, change the passwords to sites that are important and make sure you're not reusing passwords across sites and services.
Attend or watch our webinar on why password managers are important and what you can do with Keeper
If you use the same password on any of the above sites with any other important websites, change those passwords now!
What is a strong password
- Not used anywhere else
- At least 12 characters
- Include Number, Capitals, and Symbols
Keeper will make this easier by generated and saving random secure passwords. If you use BreachWatch inside Keeper, it will alert you to any passwords you should be concerned about.
Managed Services
Take a look at our Managed services to see how we can help you
Keeper Webinar
Check out our webinar to learn about Keeper and what you can do with it.
Ask us Anything
If you've got questions about Password managers, schedule an AUA with us
Security
Check out our blog for more security related posts