2025 Fowler / open Elasticsearch — ~184M login rows (plaintext passwords; May)
Data compromised
Usernames, plaintext passwords, service identifiers, and allied login metadata per researcher reporting
Technical writeup
In early May 2025, researcher Jeremiah Fowler and outlets including WIRED, DataBreaches.net, and Yahoo syndicated coverage described a ~47 GB unsecured Elasticsearch database with roughly 184,162,718 records of usernames and often plaintext passwords spanning consumer brands, financial and health logins, and a small number of .gov email paths—without clear corporate ownership. Fowler hypothesized infostealer log compilation; the host reportedly restricted public access shortly after disclosure. The incident is analytically separate from the June 2025 multi-billion “MOAB”-style infostealer pair dump and from vendor-specific MongoDB exposures.
Root cause
Internet-exposed Elasticsearch instance holding a credential compilation of unclear provenance