149M Login Leak: Facebook, TikTok, Netflix & More Affected

by priyanka.patel tech editor

Massive Data Breach Exposes Credentials of Millions Across Major Platforms

A staggering data breach has exposed the login credentials – including usernames, passwords, and email addresses – of approximately 149 million users across a vast range of popular online services, from social media giants like Facebook and TikTok to email providers Gmail and iCloud. The unsecured database, weighing 96GB, was discovered by researcher Jeremiah Fowler of the cybersecurity firm ExpressVPN.

The exposed database represents a significant risk to digital security, potentially impacting millions globally. While the origin of the data remains unknown, its public accessibility without any encryption or protective measures raises serious concerns about data security practices.

Scope of the Breach: Which Services Were Affected?

The compromised data encompasses a wide spectrum of digital services, extending beyond social media and email to include streaming platforms, financial applications, and cryptocurrency wallets. According to estimates released by ExpressVPN, the database contains credentials for:

  • 48 million Gmail accounts
  • 900,000 iCloud accounts
  • 1.5 million Outlook accounts
  • 17 million Facebook accounts
  • 6.5 million Instagram accounts
  • 780,000 TikTok accounts
  • 3.4 million Netflix accounts
  • 100,000 OnlyFans accounts
  • 420,000 Binance accounts

The breach also potentially affects users of X (formerly Twitter), HBO Max, Disney+, Roblox, and numerous other platforms.

Database Removed, But Questions Remain

ExpressVPN promptly notified the hosting provider, and the database has since been taken offline. However, the duration of the exposure remains unclear, leaving open the possibility that malicious actors had ample time to access and exploit the sensitive information. The source of the data – whether stemming from criminal activity or a legitimate, albeit poorly secured, source – is currently under investigation.

What Users Should Do Now

Although a company release stated that no personal data was compromised beyond login credentials, cybersecurity experts strongly advise users to take immediate action to mitigate potential risks. “Changing passwords across all affected services is crucial,” one analyst noted.

ExpressVPN recommends the following steps:

  • Change Passwords: Update passwords for all listed services, prioritizing those used for financial accounts or sensitive information.
  • Utilize a Password Manager: Employ a reputable password manager to generate and securely store unique, complex passwords for each account.
  • Review App Permissions: Regularly audit the permissions granted to third-party applications to limit potential access to sensitive data.
  • Update Operating Systems: Ensure all operating systems and software are updated with the latest security patches.

This incident serves as a stark reminder of the pervasive threat of data breaches and the critical importance of robust cybersecurity measures. The exposure of such a massive dataset underscores the need for heightened vigilance and proactive security practices by both individuals and organizations alike.

You may also like

Leave a Comment