You might think a password leak of this magnitude would be a single, dramatic breach. The reality is more unsettling: over 16 billion credentials have been compiled from infostealer malware, affecting users of Google, Facebook, Apple, and more. This isn’t about one company’s failure—it’s about the global habit of reusing the same passwords everywhere.

Total leaked passwords: 16 billion ·
Date discovered: July 2025 ·
Source of leak: Infostealer malware compiled by Cybernews researchers ·
Platforms affected: Google, Apple, Facebook, and others ·
Ongoing attacks: Yes, credentials being used in hack attacks

Quick snapshot

1Confirmed facts
  • The leak of 16 billion passwords is real (Cybernews)
  • The data was compiled from multiple sources by infostealer malware (Obsidian Security)
  • Credentials are being used in credential stuffing attacks (Forbes)
2What’s unclear
  • Exact number of unique passwords (duplicates may exist)
  • The specific list of the most impacted services
  • Whether any particular password manager or service suffered a new breach
3Timeline signal
  • July 2025: Cybernews researchers discover compilation of 16 billion passwords (Cybernews)
  • Mid-2025: News outlets report on the leak and its implications (AP via U.S. News)
  • December 2025: Forbes reports leaked credentials being used in ongoing attacks (Forbes)
4What’s next
  • Adopt a password manager with zero-knowledge encryption
  • Enable multi-factor authentication on all accounts
  • Replace reused passwords with unique, strong ones
  • Monitor accounts for suspicious activity

Six key numbers paint the full picture of this credential compilation.

Attribute Value
Total leaked credentials 16 billion
Leak discovery date July 2025
Primary discovery team Cybernews researchers
Affected platforms Google, Apple, Facebook, and others
Attack vector Infostealer malware
Status of attacks Ongoing; credentials used in real attacks

How to check what passwords were leaked?

The first thing to do is verify whether your credentials appear in this or any other breach. Multiple tools can help.

What passwords were leaked recently?

  • Cybernews offers a free password leak checker that scans a collection of 33 billion leaked passwords.
  • Have I Been Pwned is the most widely cited public breach lookup service for checking whether an email appears in known breaches.
  • Google Password Manager and Apple Security Recommendations can flag compromised, reused, and weak passwords on their platforms (32blog).

Were 16 billion passwords actually leaked?

Yes. Cybernews researchers identified 30 exposed datasets totaling about 16 billion login credentials, as reported by Forbes and AP. However, this is not a single breach but a compilation of exposed datasets from infostealer malware logs and credential-stuffing collections (Obsidian Security).

The upshot

The 16-billion figure aggregates many smaller leaks. Your personal risk depends on whether any of your accounts used credentials that appear in those datasets.

Bottom line: Check your email against Have I Been Pwned and use Cybernews’ checker. Change any password that appears in the leak, and don’t reuse it elsewhere.

Why are passwords being leaked?

The root cause is infostealer malware that silently harvests login credentials from infected devices. Once collected, these credentials are bundled into credential-stuffing lists used to break into accounts across the web.

What passwords do hackers usually use?

  • Hackers target reused and weak passwords for credential stuffing (Forbes).
  • Credentials from social media, VPNs, developer portals, and user accounts are common targets (Forbes).

What is the most common hacked password?

While the leak includes billions of passwords, the most common ones are predictable: simple sequences like “123456” and “password” appear frequently in compromised datasets. Security experts emphasize that any password found in a breach should be considered compromised immediately.

The pattern

The leak is a direct consequence of password reuse. If you use the same password on multiple sites, a single infostealer infection can expose all of them.

What this means: the leak isn’t a failure of any single service—it’s a systemic failure of password hygiene across the internet.

What is considered the strongest password?

A strong password is long, random, and unique per account. Avoid any password that appears in known breaches—especially the top 100 most common passwords.

What is the 8 4 rule for passwords?

  • The “8-4 rule” suggests a password of at least 8 characters including 4 different character types (uppercase, lowercase, numbers, symbols).
  • Modern guidance from the Kaspersky and Obsidian Security recommends even longer passphrases.

Which password should never be used?

  • Avoid commonly used passwords like “password”, “123456”, “admin”, and any variation of “qwerty”.
  • Never reuse passwords across different accounts—credential stuffing relies on exactly this habit.

What are the top 5 passwords?

Security research consistently lists “123456”, “password”, “12345678”, “qwerty”, and “12345” as the most common. If any of these appear in your passwords, change them immediately.

Why this matters

Using a strong, unique password for each account is the single most effective defense against credential-stuffing attacks that exploit leaks like this one.

Bottom line: A strong password has at least 12 random characters, mixes types, and is never reused. Password managers make this easy.

Where is the safest place to store my passwords?

Storing passwords securely is as important as creating strong ones. Built-in browser managers and dedicated password managers offer encrypted storage.

Which password manager has never been hacked?

  • Bitwarden and 1Password use zero-knowledge architecture and have never suffered a breach (FastestPass).
  • Google Password Manager and Apple Security Recommendations are also considered safe, as they encrypt data locally (32blog).

Choosing a password manager with zero-knowledge encryption ensures that even if the service is breached, your master password and vault remain secure.

The trade-off: convenience vs. control. Cloud-based managers offer sync across devices, while offline managers store everything locally. For most users, a reputable cloud manager with zero-knowledge design is the best balance.

What do hackers hate the most?

Multi-factor authentication (MFA) is the strongest deterrent. Hackers can steal a password, but without the second factor, they’re blocked.

  • MFA blocks automated credential-stuffing attacks (FastestPass).
  • Unique, complex passwords that resist cracking also make hackers’ work much harder.
  • Two-factor authentication (2FA) is one of the most effective deterrents, as it requires a second verification step.
The catch

MFA only helps if you enable it on every account that supports it. Even with a strong password, a single reused credential can undo all your precautions.

For users in New Zealand, the same principles apply: enable MFA on email, banking, and social accounts immediately. Related reading: Australia’s Under-16 Social Media Ban: 2026 Update covers another aspect of digital safety.

What to Do Now: Step-by-Step

Take these five steps to secure your accounts after the leak.

  1. Check your credentials using Cybernews’ password leak checker or Have I Been Pwned.
  2. Change any exposed passwords immediately—and also any other account using the same or similar password (DeepStrike).
  3. Prioritize your email account: it is often the reset point for other services (DeepStrike).
  4. Enable multi-factor authentication on every service that offers it (FastestPass).
  5. Use a password manager to generate and store unique, strong passwords for each account.

Timeline: How the Leak Unfolded

  • Early 2025 – Cybernews researchers begin analyzing infostealer malware logs and exposed datasets (Cybernews).
  • July 2025 – They discover 30 compromised datasets containing 16 billion credentials (Cybernews).
  • Mid-2025 – News outlets including Forbes, AP, and Kaspersky report the leak (Forbes, AP, Kaspersky).
  • December 2025 – Forbes reports that the leaked credentials are being actively used in hacking attacks (Forbes).

What’s Confirmed vs. Still Uncertain

Confirmed facts

  • The leak of 16 billion passwords is real.
  • The data was compiled from multiple sources by infostealer malware.
  • Credentials are being used in credential stuffing attacks.

What’s unclear

  • Exact number of unique passwords (many duplicates exist).
  • The specific list of the most impacted services.
  • Whether any password manager or service suffered a new breach.

Expert Perspectives

“We identified 30 exposed datasets totaling about 16 billion login credentials. This is not a single breach but a compilation of stolen information from various sources.”

— Cybernews researchers

“The leaked credentials are being used in ongoing hack attacks. Anyone who reuses passwords is at immediate risk.”

— Davey Winder, Forbes

“Passwordless authentication offers a long-term solution that eliminates the risk of credential theft entirely.”

— FIDO Alliance

For New Zealand readers, the practical implication is clear: take action now to protect your accounts. Related reading: Do Not Disturb iPhone: What Happens When It’s On offers another tech safety tip.

Frequently asked questions

Is the 16 billion password leak the biggest of all time?

Yes, in terms of total credentials exposed. It surpasses previous massive leaks like the 2013 Yahoo breach (3 billion accounts). However, it’s a compilation of many datasets, not a single company breach.

Should I change all my passwords immediately?

Yes, if any of your passwords appear in the leak. Start with your email account, then financial and social accounts. Use a password manager to generate and store new unique passwords.

What is infostealer malware and how does it work?

Infostealer malware is a type of malicious software that infects devices and steals saved passwords, cookies, and other credentials. The stolen data is then sold or compiled into credential-stuffing lists.

How often do large password leaks happen?

Large credential compilations occur every few months. The 16 billion leak is the largest known, but new leaks of millions to billions of credentials are discovered regularly.

Can a password manager be trusted after this leak?

Yes, provided it uses zero-knowledge encryption. Services like Bitwarden and 1Password have never been breached and encrypt your data before it leaves your device. Even if a leak occurs, your passwords remain protected.

What is credential stuffing and why is it dangerous?

Credential stuffing is an automated attack where hackers use leaked username-password pairs to attempt logins on other websites. It works because many people reuse passwords across multiple services.