According to reports by Independent security researcher Jeremiah Fowler on WebsitePlanet he discovered a massive trove of login credentials, roughly 180 million records. Advising this information has recently been exposed in an unsecured online database, posing significant risks to both individual users and the wider email ecosystem given email’s central role in digital identity and account recovery.
This has begin to be reported widely since late last week including by Wired, TechRepublic, Ghacks, Independent, Fox, The Sun, MSN and others. However as yet we have not seen infomation from sources we would expect to comment such as HaveIbeenPwnd.
Discovery of the Unprotected Database
Independent security researcher Jeremiah Fowler uncovered the cache of 184,162,718 records in May 2025 during routine scans as reported first in his post on WebsitePlanet. The misconfigured Elasticsearch database, totaling over 47 GB, was completely unprotected with no password or encryption.
“This is probably one of the weirdest ones I’ve found in many years,” Fowler said. “As far as the risk factor here, this is way bigger than most of the stuff I find, because this is direct access into individual accounts. This is a cybercriminal’s dream working list.”
Each entry included an identifier for the account type, service URL, and the user’s plaintext username and password. World Host Group shut down the database after being notified, with CEO Seb de Lemos noting “a fraudulent user signed up and uploaded illegal content to their server.”
Widespread Service Impact
Analysis revealed credentials for virtually every corner of the internet ecosystem. In a sample of 10,000 records, Fowler found hundreds of Google accounts (mostly Gmail) and Facebook logins, plus credentials for Instagram, Roblox, Discord, and “more than 100 each of Microsoft, Netflix, and PayPal accounts.”
The leak included login details for Amazon, Apple, Snapchat, Spotify, Twitter, Yahoo, banking services, healthcare platforms, and government portals. Notably, over 220 email addresses used .gov domains from at least 29 countries, including the United States, UK, Canada, Australia, China, and India, raising national security concerns.
Importantly, the affected companies, Google, PayPal, Netflix, and others – have not reported breaches of their internal systems. The compromised logins appear at least at this stage to have been collected from end-user devices or third-party breaches rather than direct infiltration of these platforms’ networks.
Infostealer Malware Origin
Investigators believe this enormous credential collection resulted from infostealer malware—malicious software that quietly harvests sensitive data from infected devices. Several clues support this theory, including the password field labeled “Senha” (Portuguese for “password”) and the breadth of account types indicating data siphoned from victims’ computers.
“It is highly possible that this was a cybercriminal [operation]… it’s the only thing that makes sense,” Fowler remarked.
Cybersecurity firms report rising infostealer attacks, with recent industry reports highlighting an 84% surge in phishing emails delivering infostealer malware in 2024 and a 58% uptick in overall infostealer attacks.
Email Security Implications
For the email industry, this breach underscores how a compromised email account can become the keys to a victim’s digital life. Email addresses serve as logins for countless services and are the primary channel for password resets and verification links.
If attackers gain control of someone’s email using these leaked credentials, they can potentially reset passwords on banking, e-commerce, or social media accounts by intercepting confirmation emails. In corporate settings, one stolen email login could lead to broader business email compromise incidents.
The inclusion of hundreds of government and enterprise email addresses is especially concerning, raising prospects of espionage or supply chain attacks if threat actors use those credentials to access official systems.
Response and Recommendations
While World Host Group’s swift database shutdown removed immediate public access, copies of the 47 GB dump could still circulate among cybercriminals. Given the volume of exposed accounts, millions of individuals are likely affected worldwide.
For Users:
- Enable multi-factor authentication (MFA), especially for high-value accounts like email, PayPal, and banking
- Use strong, unique passwords for each account via a password manager
- Change passwords immediately if you suspect your accounts might be compromised
- Monitor for unusual account activity like unfamiliar login locations or unexpected password reset emails
For Providers:
- Cross-reference leaked email addresses against user databases to flag at-risk accounts
- Enhance suspicious login detection systems
- Continue advancing passwordless authentication options like passkeys
- Educate users about infostealer malware threats
Microsoft announced in May 2025 that new accounts will be created “passwordless by default,” encouraging phishing-resistant passkeys. Google, Apple, and other companies are likewise advancing passkey support as the industry moves toward eliminating password dependence.
Industry Wake-Up Call
This incident serves as a stark reminder that vigilance and layered security are essential as credential-stealing malware feeds an ever-growing underground market. The exposure of 184 million records underscores the growing scale and severity of credential harvesting operations, which can lead to identity fraud, unauthorized access, and widespread breaches.
Email providers and professionals must continue adapting to ensure that a single leaked password cannot so easily open the door to an individual’s entire digital life.








