People search Mother of All Breaches data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 9 Mother of All Breaches-linked incidents, with headline counts up to 26B+ in catalog rows. This page maps every attested event through 2026 with internal links to canonical records.
Why Mother of All Breaches breach history matters
Mother of All Breaches operates in Technology. Across indexed rows, recurring themes include credential theft and social engineering, cloud and database misconfiguration, third-party and supply-chain exposure, zero-day exploitation and malware, unverified actor or scraping claims. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — alleged IBAN/bank financial records (sxxmj; June)
Unverified claim — treat actor counts cautiously. In early June 2026, VECERT-style monitors described forum marketing by actor sxxmj alleging Spanish IBAN and banking financial records. No Spanish regulator or bank consortium notice had been indexed at catalog time. BreachHistory uses the existing MOAB compilation entity for brokered multi-source financial leaks until a named institution confirms scope. Exposed categories include Alleged IBAN, BIC, and account-holder financial fields per actor marketing. No attested victim count is published for this row yet. See the spain-iban-sxxmj 2026 record and canonical BreachHistory entry.
2026 — stalkerware DB exposed 86,859 screenshots; celebrity/influencer chats leaked
Cataloged incident. Cybersecurity researcher Jeremiah Fowler discovered a publicly accessible, non-password-protected database containing 86,859 screenshots apparently collected by stalkerware installed on a single prominent European celebrity’s device. ExpressVPN (April 30, 2026) and ITWire (June 11, 2026) reported the leak exposed private chats with models, influencers, and celebrities across Facebook, WhatsApp, Instagram, and TikTok, plus documents, phone numbers, and emails of third parties who never consented to surveillance. Fow Exposed categories include 86,859 device screenshots: WhatsApp, Instagram, Facebook, TikTok chats with celebrities/influencers; IDs, invoices, phone numbers. BreachHistory cites approximately 87K+ affected records in this row. See the stalkerware-celebrity-screenshots 2026 r and canonical BreachHistory entry.
2026 — ~149M login rows in open DB (~96 GB); infostealer aggregation (Jan)
Cataloged incident. In January 2026, researcher Jeremiah Fowler and outlets including WIRED and ExpressVPN described a publicly reachable, unencrypted database of roughly 149,404,754 credential-oriented rows (~96 GB) spanning usernames, passwords, and login URLs—interpreted as primarily infostealer malware output aggregated into a single warehouse rather than one brand’s SQL breach. The corpus was reported as still growing during responsible-disclosure coordination with the host. Treat headline counts as log-derived credential lines, Exposed categories include Usernames, passwords, service login URLs per researcher reporting. BreachHistory cites approximately 149.4M+ affected records in this row. See the open-database-149m-infostealer- 2026 rec and canonical BreachHistory entry.
2026 — open French cloud DB; ~45M aggregated voter/health/finance/vehicle rows (Jan)
Cataloged incident. On January 14, 2026, Cybernews reported discovery of an unprotected cloud server in France holding more than 45 million records assembled from multiple unrelated sources—described as voter or demographic registries (~23M+ rows), healthcare professional listings resembling RPPS/ADELI mirrors (~9.2M), CRM contacts (~6M), financial profiles with IBAN/BIC fields (~6M), and vehicle or insurance-oriented tables. Analysts characterized the repository as a criminal or broker compilation for identity cross-linking rather th Exposed categories include Voter-style demographics, healthcare professional metadata, CRM contacts, IBAN/BIC financial rows, and automotive or insurance records per Cybernews. BreachHistory cites approximately 45M+ affected records in this row. See the france-open-database-45m- 2026 record and canonical BreachHistory entry.
2026 — exposed Elasticsearch (Hetzner); ~3B+ emails/passwords & ~2.7B+ SSN-class rows (Jan)
Cataloged incident. In January 2026, UpGuard researchers publicly documented a massive unsecured Elasticsearch instance on Hetzner infrastructure containing on the order of three billion email-and-password-oriented records and roughly 2.7 billion rows with U.S. Social Security numbers, characterized in reporting as a long-lived aggregated or broker-style warehouse rather than a single consumer brand’s production database. Discovery was widely placed around the week of January 12, 2026, with remediation after outreach to IC3 and the ho Exposed categories include Email addresses, password strings, SSN fields, and allied credential or identity metadata per researcher disclosure. BreachHistory cites approximately 5.7B+ affected records in this row. See the upguard-elasticsearch-social-insecurity- and canonical BreachHistory entry.
2026 — exposed Elasticsearch; ~8.7B Chinese citizen/business records (Jan)
Cataloged incident. Cybernews and follow-on trade coverage described an unsecured Elasticsearch cluster discovered January 1, 2026, holding on the order of 8.73 billion records tied to Chinese individuals and businesses across more than 160 indices, including national ID–style numbers, names, addresses, mobile numbers, plaintext or weakly protected passwords, and business registration–oriented tables. Researchers framed the corpus as a deliberate multi-year aggregation likely associated with data-broker or criminal collection rather t Exposed categories include National IDs, demographic and contact fields, passwords, social handles, and business records per Cybernews. BreachHistory cites approximately 8.7B+ affected records in this row. See the china-elasticsearch-8.7b- 2026 record and canonical BreachHistory entry.
2025 — ~16B login pairs publicized (June)
Cataloged incident. In June 2025, researchers and major outlets (Cybernews, Forbes, FIDO Alliance commentary, university cybersecurity briefings) publicized a colossal aggregated dump on the order of 16 billion username-password pairs sourced primarily from years of infostealer malware logs rather than a single company SQL breach. Narratives emphasized password hygiene, phishing resistance, and hardware-backed MFA because many brands appeared as “affected” through stolen client credentials rather than direct server compromise. Exposed categories include Credential pairs and allied metadata from stealer ecosystems. BreachHistory cites approximately 16B+ affected records in this row. See the credential-compilation-infostealer-2025 and canonical BreachHistory entry.
2025 — ~184M login rows (plaintext passwords; May)
Cataloged incident. In early May 2025, researcher Jeremiah Fowler and outlets including WIRED, DataBreaches.net, and Yahoo syndicated coverage described a ~47 GB unsecured Elasticsearch database with roughly 184,162,718 records of usernames and often plaintext passwords spanning consumer brands, financial and health logins, and a small number of .gov email paths—without clear corporate ownership. Fowler hypothesized infostealer log compilation; the host reportedly restricted public access shortly after disclosure. The incident is anal Exposed categories include Usernames, plaintext passwords, service identifiers, and allied login metadata per researcher reporting. BreachHistory cites approximately 184.2M+ affected records in this row. See the open-elasticsearch-184m-logins-2025 and canonical BreachHistory entry.
2024 — 26B records
Cataloged incident. Jan 2024. Twitter, Adobe, Canva, LinkedIn, Dropbox. 26B records. Exposed categories include Emails, passwords from multiple sources. BreachHistory cites approximately 26B+ affected records in this row. See the mother-of-all-breaches-2024 and canonical BreachHistory entry.
Patterns and analysis
- Credential theft and social engineering — appears across multiple Mother of All Breaches catalog entries; prioritize controls that address this class of failure.
- Cloud and database misconfiguration — appears across multiple Mother of All Breaches catalog entries; prioritize controls that address this class of failure.
- Third-party and supply-chain exposure — appears across multiple Mother of All Breaches catalog entries; prioritize controls that address this class of failure.
- Zero-day exploitation and malware — appears across multiple Mother of All Breaches catalog entries; prioritize controls that address this class of failure.
- Unverified actor or scraping claims — appears across multiple Mother of All Breaches catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Review OAuth app permissions and revoke unused third-party integrations.
- Step 5: Bookmark the Mother of All Breaches company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/moab · Latest: spain-iban-sxxmj2026.
Sources: BreachHistory catalog (9 rows for Mother of All Breaches), company and regulator disclosures cited in individual breach records.