Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

BREAKING: 16 BILLION Passwords Leaked! Apple, Google, Facebook and More!
100 Percent Fed Up ^ | June 19, 2025 | M Winger

Posted on 06/19/2025 11:41:00 AM PDT by Red Badger

I’ll keep this short and sweet so I can get this out faster to you.

As headline says, 16,000,000,000 passwords have been leaked.

Most likely the biggest password leak in history.

It would probably be a good idea to change your passwords.

If you have Google, maybe start there and change your Google password, since a lot of people have numerous saved passwords to bank accounts, social media accounts, email, etc, all under Google.

Forbes:

Update, June 19, 2025: This story, originally published on June 18, has been updated with comments from the founders of Keeper Security regarding the 16 billion leaked passwords and other login credentials across the major tech vendor landscape.

If you thought that my May 23 report, confirming the leak of login data totaling an astonishing 184 million compromised credentials, was frightening, I hope you are sitting down now. Researchers have just confirmed what is also certainly the largest data breach ever, with an almost incredulous 16 billion login credentials, including passwords, exposed. As part of an ongoing investigation that started at the beginning of the year, the researchers have postulated that the massive password leak is the work of multiple infostealers. Here’s what you need to know and do.

Is This The GOAT When It Comes To Passwords Leaking? Password compromise is no joke; it leads to account compromise and that leads to, well, the compromise of most everything you hold dear in this technological-centric world we live in. It’s why Google is telling billions of users to replace their passwords with much secure passkeys. It’s why the FBI is warning people not to click on links in SMS messages. It’s why stolen passwords are up for sale, in their millions, on the dark web to anyone with the very little amount of cash required to purchase them. And it’s why this latest revelation is, frankly, so darn concerning for everyone.

According to Vilius Petkauskas at Cybernews, whose researchers have been investigating the leakage since the start of the year, “30 exposed datasets containing from tens of millions to over 3.5 billion records each,” have been discovered. In total, Petkauskas has confirmed, the number of compromised records has now hit 16 billion. Let that sink in for a bit. These collections of login credentials, these databases stuffed full of compromised passwords, comprise what is thought to be the largest such leak in history.

Thieves among us. Protect your data!

This is a Guest Post from our friends over at WLTReport.

View the original article here.Forbes:

Update, June 19, 2025: This story, originally published on June 18, has been updated with comments from the founders of Keeper Security regarding the 16 billion leaked passwords and other login credentials across the major tech vendor landscape.

If you thought that my May 23 report, confirming the leak of login data totaling an astonishing 184 million compromised credentials, was frightening, I hope you are sitting down now. Researchers have just confirmed what is also certainly the largest data breach ever, with an almost incredulous 16 billion login credentials, including passwords, exposed. As part of an ongoing investigation that started at the beginning of the year, the researchers have postulated that the massive password leak is the work of multiple infostealers. Here’s what you need to know and do.

Is This The GOAT When It Comes To Passwords Leaking? Password compromise is no joke; it leads to account compromise and that leads to, well, the compromise of most everything you hold dear in this technological-centric world we live in. It’s why Google is telling billions of users to replace their passwords with much secure passkeys. It’s why the FBI is warning people not to click on links in SMS messages. It’s why stolen passwords are up for sale, in their millions, on the dark web to anyone with the very little amount of cash required to purchase them. And it’s why this latest revelation is, frankly, so darn concerning for everyone.

According to Vilius Petkauskas at Cybernews, whose researchers have been investigating the leakage since the start of the year, “30 exposed datasets containing from tens of millions to over 3.5 billion records each,” have been discovered. In total, Petkauskas has confirmed, the number of compromised records has now hit 16 billion. Let that sink in for a bit. These collections of login credentials, these databases stuffed full of compromised passwords, comprise what is thought to be the largest such leak in history.

Thieves among us. Protect your data!

This is a Guest Post from our friends over at WLTReport.

View the original article here.

https://wltreport.com/2025/06/19/breaking-16-billion-passwords-leaked-apple-google-facebook/#utm_source=rss&utm_medium=rss&utm_campaign=breaking-16-billion-passwords-leaked-apple-google-facebook


TOPICS: Business/Economy; Crime/Corruption; Culture/Society
KEYWORDS: apple; bigdata; cloud; computers; data; datamining; facebook; google; internet; keepersecurity; passwords
Navigation: use the links below to view more comments.
first previous 1-2021-4041-44 next last
To: Red Badger

Should I change all the main ones?


21 posted on 06/19/2025 12:45:23 PM PDT by RWGinger
[ Post Reply | Private Reply | To 18 | View Replies]

To: Red Badger
Storing passwords in the clear would be a significant security risk, and companies adhere to industry standards to hash passwords, making it computationally infeasible to reverse them to plaintext. Apple, Facebook (Meta), and Google do not store passwords in the clear. They store passwords as hashes using secure cryptographic algorithms. Below is a summary of their practices:

BUT, the 16 Billion Record Breach Still Matters Despite Hashed Passwords

The issue stems from how these credentials were stolen, bypassing server-side protections:

What to Do

Summary

The breach is a threat because malware stole plaintext credentials from devices, not hashed data from servers. The data’s scale and freshness make account takeovers likely without 2FA or unique passwords. Act now to secure accounts and devices.
My practices:

I use Apple and LastPas to generate passwords. Here's one I just created in LastPass: cgQyFiJ10nyj4xd&. I gave up trying to make memorizable passwords and started using LastPass about 15 years ago. But those tough passwords force you into using a password manager. I like the integration of Apple's password generator and manager into Mac and IOS, but I stick with LastPass for a lot of other features.

Another approach is to use a long "passphrase" which is a phrase or sentence like "FreeRepublicIsTheGreatestEver." You can toss in a few number/letter substitutions to make it impossible to crack. "FrEeRepublicI$TheGreatestEver". Many people will say never use real words in your passphrase, so sprinkling a few numbers and symbols helps with that.

But the longest, most complicated password in the world doesn't help you if you let malware onto your machines or you fall for "social engineering" attacks and give your password to a stranger.

Use anti-malware scanning software for real-time protection and run scans on your machine regularly. That will keep key loggers off your machine.

Be sure to use Two Factor Authentication everywhere you can.

Be sure to set up SIM Swap Fraud on our mobile carrier account. This secures your mobile account and personal information to stop criminals from transferring your phone number to a SIM card they control.

22 posted on 06/19/2025 12:47:09 PM PDT by ProtectOurFreedom (“Diversity is our Strength” just doesn’t carry the same message as “Death from Above”)
[ Post Reply | Private Reply | To 1 | View Replies]

To: RWGinger

The only one of that group I have a password with is Google. And it can be changed at any time. If I had all those mentioned I change them all ASAP................


23 posted on 06/19/2025 12:48:28 PM PDT by Red Badger (Homeless veterans camp in the streets while illegals are put up in 5 Star hotels....................)
[ Post Reply | Private Reply | To 21 | View Replies]

To: Red Badger
"The companies you do business with have all your passwords stored somewhere in the computers"

Yes and no. Say you create a password like: "ILoveFreeRepublic"

This is what gets stored by the company on its server:
MD5 Hash: 0000b37e5e1a2e844f1bf35bc93136ff
SHA1 Hash: f09916591150638dd6fdccc1e2499721cc63afe6

Hash functions do not allow you to reverse the hash to get back the original password. It's a one-way trip! Even the company doesn’t know your password.

24 posted on 06/19/2025 12:59:05 PM PDT by ProtectOurFreedom (“Diversity is our Strength” just doesn’t carry the same message as “Death from Above”)
[ Post Reply | Private Reply | To 13 | View Replies]

To: ProtectOurFreedom
Say you create a password like: "ILoveFreeRepublic"

You would be immediately kicked out and banned from every lib company website on earth..............

25 posted on 06/19/2025 1:00:59 PM PDT by Red Badger (Homeless veterans camp in the streets while illegals are put up in 5 Star hotels....................)
[ Post Reply | Private Reply | To 24 | View Replies]

To: Red Badger
"Wrong. The companies you do business with have all your passwords stored somewhere in the computers......................"

Not exactly - any competent tech company, especially the ones named in the article, Apple, Google, Facebook, will never store your password. They store a one way hash of your password. So when you login, they compare the hash they have stored, with a fresh hash of the password you are supplying. If they match you are logged in. This means if the database at Apple, Google, Facebook get stolen, the thief gets the hash, but not the password.

It is not foolproof, your password still gets transmitted during login, and if the hash is stolen, you can make guesses to match it. But if you are using unique, hard to guess password, you are probably not at risk of your password being stolen.


26 posted on 06/19/2025 1:02:16 PM PDT by Wayne07
[ Post Reply | Private Reply | To 13 | View Replies]

To: Red Badger

LOL...yes. In fact, the number of companies that would keep you can probably be counted on both hands.


27 posted on 06/19/2025 1:02:47 PM PDT by ProtectOurFreedom (“Diversity is our Strength” just doesn’t carry the same message as “Death from Above”)
[ Post Reply | Private Reply | To 25 | View Replies]

To: ProtectOurFreedom

A few years back I read an article that some companies websites will read your cookies to see what websites you visited and if you weren’t of the right mind according to their definition you would not be allowed access to their site, products or services.......


28 posted on 06/19/2025 1:07:33 PM PDT by Red Badger (Homeless veterans camp in the streets while illegals are put up in 5 Star hotels....................)
[ Post Reply | Private Reply | To 27 | View Replies]

To: Red Badger
16,000,000,000 passwords have been leaked.

Well, they'll have to go thru 15,999,999,999 to get to mine.

29 posted on 06/19/2025 1:12:05 PM PDT by Hot Tabasco
[ Post Reply | Private Reply | To 1 | View Replies]

To: Hot Tabasco

We used to have a lady at work that put all her passwords on Post-It notes all over her monitor and cubicle wall..............


30 posted on 06/19/2025 1:13:16 PM PDT by Red Badger (Homeless veterans camp in the streets while illegals are put up in 5 Star hotels....................)
[ Post Reply | Private Reply | To 29 | View Replies]

To: Red Badger

If anybody finds out who these hackers are, I’ll be happy to help string them up.


31 posted on 06/19/2025 1:16:06 PM PDT by Tolerance Sucks Rocks (FBI out of Florida!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Tolerance Sucks Rocks

They are probably in North Korea or China................


32 posted on 06/19/2025 1:17:06 PM PDT by Red Badger (Homeless veterans camp in the streets while illegals are put up in 5 Star hotels....................)
[ Post Reply | Private Reply | To 31 | View Replies]

To: Red Badger

I have no problem with wiping Beijing or Pyongyang off the map. The blowback would be worrisome, however.


33 posted on 06/19/2025 1:21:49 PM PDT by Tolerance Sucks Rocks (FBI out of Florida!)
[ Post Reply | Private Reply | To 32 | View Replies]

To: Red Badger

Bkmk


34 posted on 06/19/2025 1:33:39 PM PDT by ptsal (Vote R.E.D. >>>Remove Every Democrat ***)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Bkmk


35 posted on 06/19/2025 1:39:59 PM PDT by ptsal (Vote R.E.D. >>>Remove Every Democrat ***)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Fortunately I don’t work anymore so the sticky notes with all my passwords stuck all over the desk in my den are safe......


36 posted on 06/19/2025 1:49:00 PM PDT by Hot Tabasco
[ Post Reply | Private Reply | To 30 | View Replies]

To: Red Badger

Mine is 12345.

It is also President Skroob’s combination to his luggage and the air shield.


37 posted on 06/19/2025 1:56:13 PM PDT by moviefan8
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

Hah! I can beat that ....

CAT

!!!!!!!!


38 posted on 06/19/2025 2:18:02 PM PDT by fruser1
[ Post Reply | Private Reply | To 3 | View Replies]

To: Red Badger

This is why it should be illegal for companies such as Microsoft to require windows users to create an account with them.


39 posted on 06/19/2025 2:24:16 PM PDT by Revel
[ Post Reply | Private Reply | To 1 | View Replies]

To: Red Badger

If it’s been hacked won’t they obtain my new passwords when I change them?


40 posted on 06/19/2025 2:26:18 PM PDT by Flaming Conservative ((Pray without ceasing))
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first previous 1-2021-4041-44 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson