← Mother of All Breaches

2026 Fowler — ~149M login rows in open DB (~96 GB); infostealer aggregation (Jan)

2026 149.4M records affected Share on X

Data compromised

Usernames, passwords, service login URLs per researcher reporting

Technical writeup

In January 2026, researcher Jeremiah Fowler and outlets including WIRED and ExpressVPN described a publicly reachable, unencrypted database of roughly 149,404,754 credential-oriented rows (~96 GB) spanning usernames, passwords, and login URLs—interpreted as primarily infostealer malware output aggregated into a single warehouse rather than one brand’s SQL breach. The corpus was reported as still growing during responsible-disclosure coordination with the host. Treat headline counts as log-derived credential lines, not unique living users; heavy overlap with prior combo lists is expected.

Root cause

Internet-exposed datastore holding stealer-log compilation

References