2026 Fowler — ~149M login rows in open DB (~96 GB); infostealer aggregation (Jan)
Data compromised
Usernames, passwords, service login URLs per researcher reporting
Technical writeup
In January 2026, researcher Jeremiah Fowler and outlets including WIRED and ExpressVPN described a publicly reachable, unencrypted database of roughly 149,404,754 credential-oriented rows (~96 GB) spanning usernames, passwords, and login URLs—interpreted as primarily infostealer malware output aggregated into a single warehouse rather than one brand’s SQL breach. The corpus was reported as still growing during responsible-disclosure coordination with the host. Treat headline counts as log-derived credential lines, not unique living users; heavy overlap with prior combo lists is expected.
Root cause
Internet-exposed datastore holding stealer-log compilation
References
- https://www.wired.com/story/149-million-stolen-usernames-passwords/
- https://www.expressvpn.com/blog/149m-infostealer-data-exposed/
- https://www.itsecurityguru.org/2026/01/27/149-million-compromised-credentials-expose-growing-infostealer-malware-crisis/
- https://www.acilearning.com/blog/the-biggest-cybersecurity-breaches-of-2026-so-far-and-the-training-that-could-have-prevented-them/
- https://www.pkware.com/blog/2026-data-breaches
- https://www.securitymagazine.com/articles/102095-149m-credentials-exposed-facebook-instagram-government-and-more-included