Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Cybernews reported finding 16 billion credential records across 30 exposed datasets in June 2025. That is a raw record total—not 16 billion people, unique accounts, or a confirmed breach of Apple, Google, Facebook, or any other named service. The datasets may contain duplicates and overlap, and their origins and owners were not fully established.

What does the 16 billion figure mean?

Cybernews reported that researchers found 30 exposed datasets, ranging in size from tens of millions to more than 3.5 billion records each. The publication gave an average of about 550 million records per dataset and a combined total of 16 billion credential records. Those are the report’s figures, published in 2025—not a verified count of unique people.

Cybernews said researchers could not reliably compare every dataset to identify duplicates, and that overlap was likely. A single person’s credentials could therefore appear more than once, or across different datasets. The available reporting does not establish how many unique people or accounts were represented. Cybernews’ report and subsequent clarifications explain the count and its limits.

Was this one breach of Apple, Google, or Facebook?

No such centralized breach was established. Cybernews contributor and security researcher Bob Diachenko said, “There was no centralized data breach at any of these companies,” referring to Apple, Google, and Facebook. Some records included login URLs for those services, but that does not show that the services’ own systems were breached.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Credentials associated with a service can be collected from a user’s infected device or appear in previously circulated credential lists. The distinction is between credentials that can be used to access an account and proof that the account provider itself suffered an intrusion. The report supports the former, not a claim of a single breach of those companies.

What kinds of records were in the datasets?

Cybernews described the material as a likely mixture of infostealer logs, credential-stuffing sets, and older, recycled leaks. Researchers observed records often formatted with a URL followed by login details and a password. That pattern is consistent with infostealer logs, but it does not prove that every record came from the same source or that all 30 datasets had one origin.

The report also discusses session cookies and tokens. These can be relevant to account access separately from a password: changing a password may not end every existing session or invalidate every token. Whether a particular record included a usable cookie or token is not established for every dataset.

What does it mean for you?

The report is a reason to review account security, not evidence that any particular reader’s account was included. TechRadar’s June 19, 2025 coverage said the databases were available to the wider internet only briefly and that their owners could not be identified. The number of people who may have accessed or copied them was not established, so neither the period of exposure nor the number of affected people can be treated as a verified victim count. TechRadar’s contemporaneous report describes those uncertainties.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Take these account-specific steps:

  1. Replace reused or weak passwords. Change them on any account where you reused the same password or believe the credential may have been exposed. Give each account a different, strong password; a password manager can help create and keep track of unique credentials.
  2. Enable multifactor authentication (MFA). Turn it on for important accounts wherever the provider offers it. Use an MFA method supported by that account and device.
  3. Review account activity. Look for sign-ins, security alerts, or changes you do not recognize. If anything is suspicious, contact the service through its official support channel.
  4. End sessions if you suspect session theft. Use the provider’s official instructions to sign out of other sessions or revoke tokens, as well as changing the password. A password change alone may not reset every cookie or token.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Can you check whether your information was included?

You can check an email address with a reputable breach-notification service, but the result depends on which datasets that service has indexed. Have I Been Pwned offers a general email breach check; its page does not confirm that this particular collection is included. A clean result therefore cannot prove that your credentials were absent from these datasets.

  • Do not download purported breach files to search them yourself.
  • Do not enter a password into an unfamiliar checker. A breach check should not need your account password.
  • Be cautious with unsolicited messages claiming to reveal whether you were affected; verify account alerts through the service’s official website or app.

What remains unknown?

  • The number of unique people or accounts represented; the total is not deduplicated.
  • The full origins and owners of all 30 datasets.
  • How many people viewed or copied the exposed material.
  • Whether any particular reader’s credentials appeared in the collection.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.