← Mother of All Breaches

2026 UpGuard — exposed Elasticsearch (Hetzner); ~3B+ emails/passwords & ~2.7B+ SSN-class rows (Jan)

2026 5.7B records affected Share on X

Data compromised

Email addresses, password strings, SSN fields, and allied credential or identity metadata per researcher disclosure

Technical writeup

In January 2026, UpGuard researchers publicly documented a massive unsecured Elasticsearch instance on Hetzner infrastructure containing on the order of three billion email-and-password-oriented records and roughly 2.7 billion rows with U.S. Social Security numbers, characterized in reporting as a long-lived aggregated or broker-style warehouse rather than a single consumer brand’s production database. Discovery was widely placed around the week of January 12, 2026, with remediation after outreach to IC3 and the host by January 21, 2026, in UpGuard’s narrative. Overlap with prior public dumps and stealer logs is expected; treat headline billions as raw row counts, not unique living individuals.

Root cause

Internet-exposed Elasticsearch cluster; misconfiguration or negligent hosting of a data aggregator

References