“24 billion usernames and passwords found sitting wide open on the internet. That's roughly 3 logins for every human alive... Researchers found an 8.3TB database left online with no password on it... Much of it in plaintext... Where did it come from? Mostly infostealer malware... Then it gets traded on Telegram like footy cards... nobody…”
Plain restatementAn exposed online database of roughly 8.3 TB containing about 24 billion credential records (usernames, emails, passwords, and login URLs) was discovered by researchers. Much of the data was in plaintext, largely sourced from infostealer malware logs and Telegram-distributed breach compilations. The number of unique individuals affected is unknown due to unknown duplication.
This claim is mostly accurate. Cybernews researchers reported finding an unsecured 8.3 TB Elasticsearch database containing about 24 billion credential records, largely sourced from infostealer malware logs and Telegram-distributed breach compilations, with much of it in plaintext. The post correctly notes that the number of duplicates is unknown and that 24 billion records does not equal 24 billion distinct people. A small simplification is that the 24 billion figure refers to records (which also include emails and login URLs), not strictly 24 billion unique username-password pairs. The practical advice in the post, checking Have I Been Pwned, changing reused passwords, and enabling two-factor authentication, is consistent with standard guidance for this kind of exposure.
24 billion usernames [drifted from the evidence:] and passwords [drifted from the evidence:] found sitting wide open on the internet. That's roughly 3 logins for every human alive... Researchers [drifted from the evidence:] found an 8.3TB database left online with no password on it... Much of [drifted from the evidence:] it in plaintext... [drifted from the evidence:] Where did it come from? [drifted from the evidence:] Mostly infostealer malware... [drifted from the evidence:] Then it gets traded on Telegram like footy cards... nobody knows how many of the [drifted from the evidence:] 24 billion are duplicates. It's not 24 billion separate people.
[added by the neutral restatement:] An exposed online database of roughly 8.3 TB containing about 24 billion [added by the neutral restatement:] credential records (usernames, [added by the neutral restatement:] emails, passwords, [added by the neutral restatement:] and login URLs) was discovered by researchers. Much of [added by the neutral restatement:] the data was in plaintext, [added by the neutral restatement:] largely sourced from infostealer malware [added by the neutral restatement:] logs and Telegram-distributed breach compilations. The [added by the neutral restatement:] number of unique individuals affected is unknown due to unknown duplication.
Red-tinted words in the claim drifted from the evidence. Green-tinted words are what a neutral restatement needs.
The trace / claim to source
- A database of about 24 billion credential records and 8.3 TB was discovered exposed online without authentication.
- Much of the content was in plaintext, listing passwords alongside the associated login URLs.
- The data was largely sourced from infostealer malware and traded/aggregated via Telegram channels and breach compilations.
- The number of duplicates and unique victims is not known.
- The 24 billion figure is roughly three times the world's population, so "3 logins for every human alive" is a fair back-of-envelope ratio (not a claim that 3 accounts exist per person).
- Minor framing: the post's phrasing "24 billion usernames and passwords" is slightly narrower than what researchers described. The dataset is 24 billion "records" that also include emails and URLs, not 24 billion distinct username-password pairs. This is a common simplification in secondary reporting and does not materially change the meaning, especially because the post itself later notes duplicates are unknown.
- "3 logins for every human alive" is a rhetorical ratio, not a per-person estimate. The post explicitly disclaims this, which mitigates the risk of misreading.
- The proportion of the 24 billion records that are duplicates versus unique credentials. Cybernews explicitly states this is not yet known.
- The exact number of unique individuals affected.
- Attribution: who compiled and hosted the database has not been publicly identified in the sources reviewed.
The Cybernews research team reports that they found an exposed Elasticsearch cluster containing 24 billion records and more than 8.3TB of data, with most records appearing to be infostealer logs, including usernames, emails, passwords, and login URLs . The data came from 36 sources, including Telegram channels, breach compilations, and large "collections." Researchers cannot yet confirm how many records are duplicates or how many unique people were affected. Secondary reporting confirms the database was publicly reachable without authentication and has since been taken offline, with the data reportedly coming from 36 sources including numerous Telegram channels, prior breach compilations , and infostealer malware output.
Complete reasoning
The reply receipt is formatted for pasting into the thread where the claim is circulating.
Compact share page: verify.trueseeker.com/s/7f2919634b63/FVfZ-PiJSr0VLhKUerJTjoX
Ask this case
Answers come only from the case file above; nothing is added.
Was there really a database of 24 billion credential records left open on the internet?
Yes. Cybernews researchers found an unsecured Elasticsearch database containing about 24 billion records totaling more than 8.3 TB, publicly reachable without any password. It has since been taken offline.
Does this mean 24 billion people had their logins exposed?
No. The 24 billion figure counts records, not unique people, and the number of duplicates is unknown. Researchers explicitly stated they could not confirm how many distinct individuals were affected.
Were the passwords really stored in plaintext?
Much of the data was in plaintext, with passwords listed alongside their associated login URLs, according to the Cybernews research report.
Where did all this data come from?
The data was drawn from 36 sources, including infostealer malware logs, prior breach compilations, and Telegram channels where such data is traded and shared.
Do investigators know who put the database together or who hosted it?
No. The case file states that who compiled and hosted the database has not been publicly identified.