← Mother of All Breaches

2025 Fowler / open Elasticsearch — ~184M login rows (plaintext passwords; May)

2025 184.2M records affected Share on X

Data compromised

Usernames, plaintext passwords, service identifiers, and allied login metadata per researcher reporting

Technical writeup

In early May 2025, researcher Jeremiah Fowler and outlets including WIRED, DataBreaches.net, and Yahoo syndicated coverage described a ~47 GB unsecured Elasticsearch database with roughly 184,162,718 records of usernames and often plaintext passwords spanning consumer brands, financial and health logins, and a small number of .gov email paths—without clear corporate ownership. Fowler hypothesized infostealer log compilation; the host reportedly restricted public access shortly after disclosure. The incident is analytically separate from the June 2025 multi-billion “MOAB”-style infostealer pair dump and from vendor-specific MongoDB exposures.

Root cause

Internet-exposed Elasticsearch instance holding a credential compilation of unclear provenance

References