# 16 Billion Apple, Facebook, Google And Other Passwords Leaked — Act Now

**URL:** https://discuss.privacyguides.net/t/16-billion-apple-facebook-google-and-other-passwords-leaked-act-now/28475
**Category:** News
**Tags:** article
**Created:** 2025-06-19T13:23:18Z
**Posts:** 19

## Post 1 by @yes — 2025-06-19T13:23:18Z

> **[16 Billion Apple, Facebook, Google And Other Passwords Leaked](https://www.forbes.com/sites/daveywinder/2025/06/20/16-billion-apple-facebook-google-passwords-leaked---change-yours-now/)**
>
> As 16 billion credentials are confirmed as having been leaked, is it time to switch from passwords to passkeys?

> According to Vilius Petkauskas at Cybernews, whose researchers have been investigating the leakage since the start of the year, “30 exposed datasets containing from tens of millions to over 3.5 billion records each,” have been discovered. In total, Petkauskas has confirmed, the number of compromised records has now hit 16 billion. Let that sink in for a bit. These collections of login credentials, these databases stuffed full of compromised passwords, comprise what is thought to be the largest such leak in history.

> The 16 billion strong leak, housed in a number ion supermassive datasets, includes billions of login credentials from social media, VPNs, developer portals and user accounts for all the major vendors. Remarkably, I am told that none of these datasets have been reported as leaked previously, this is all new data. Well, almost none: the 184 million password database I mentioned at the start of the article is the only exception.

---

## Post 2 by @anonymous261 — 2025-06-19T13:28:48Z

[@team](/groups/team) I think this topic should be pinned, this is dire

---

## Post 3 by @Anvil — 2025-06-19T13:48:45Z

I’m not able to find a list of the compromised services. Most of the articles about it just say that it was vaguely “a lot.” Not even sure if any accounts I care about could be affected.

---

## Post 4 by @PaleCrow55 — 2025-06-19T13:52:12Z

Is it confirmed if the password leaks are hash+salt databases vs the original passwords?

---

## Post 5 by @Breeze7846 — 2025-06-19T13:52:30Z

[https://cybernews.com/security/billions-credentials-exposed-infostealers-data-leak/](https://cybernews.com/security/billions-credentials-exposed-infostealers-data-leak/)

“Information in the leaked datasets opens the doors to pretty much any online service imaginable, from Apple, Facebook, and Google, to GitHub, Telegram, and various government services. It’s hard to miss something when 16 billion records are on the table.”

Unless you just don’t use the internet, it would look like pretty much any service is at risk. Getting more details is good, I agree, but this might be a 10/10 bad.

I just wonder if this data will become registered on services like haveibeenpwned. They said that not all of this data was posted for long…

---

## Post 6 by @anonymous261 — 2025-06-19T14:36:57Z

Should OTP secrets be reset as well?

---

## Post 8 by @PaleCrow55 — 2025-06-19T18:20:55Z

From what I can tell, this isn’t necessarily due to password _managers_ being leaked, but data from services that need to authenticate passwords being somewhat insecure at times; either from the hash databases being leaked, or passwords themselves being transmitted insecurely. Even if you use a stateless manager, you still need to send data to the service.

EDIT: post I was replying to seems to have been deleted?

---

## Post 9 by @Prismatic — 2025-06-19T19:04:24Z

I don’t think any services were breached.

> The data most likely originates from various infostealers.

> Researchers claim that most of the data in the leaked datasets is a mix of details from stealer malware, credential stuffing sets, and repackaged leaks.

---

## Post 10 by @arise1984 — 2025-06-19T19:37:30Z

Most of other reports about the breach claimed that its source might be from local malware or infostealer, not the first party google, amazon, facebook themselves being breached. Thats a classic forbes sensational clickbait title. Fucking forbes.

---

## Post 11 by @Neo1 — 2025-06-20T15:20:37Z

Typical mainstream media fake news right here. Don’t believe everything you read.

---

## Post 12 by @anonymous347 — 2025-06-20T15:29:17Z

> [@anonymous261](#):
>
> I think this topic should be pinned, this is dire

> [@Neo1](#):
>
> Typical mainstream media fake news right here.

Privacy Guides threads in a nutshell :joy:

---

## Post 13 by @Securely0845 — 2025-06-20T15:35:24Z

Yeah, I can’t find any legitimate articles that say this is anything other than a newly discovered dataset of previous infostealer data, the Cybernews article that claims there is new data in the data set doesn’t have a way to validate that as they didn’t have access to the data set long enough to confirm anything, per their own article, the Bleepingcomputer article basically says it’s just old data.

I wouldn’t say it’s a total nothingburger, it’s always good to have reminders to maintain good password hygiene, but I don’t think anyone needs to run out and change all their account passwords, especially if you are using real 2FA (not just sms) or passkeys.

---

## Post 14 by @benm — 2025-06-20T17:25:59Z

The implication of this data breach is a widespread undetected malware or phishing method and as such I would think that OTP’s could be compromised as well.

---

## Post 15 by @nobrowser — 2025-06-20T19:16:27Z

> real 2FA (not just sms)

I think this might be more complicated, depending on usage. I’m an old dinosaur still using a “desktop”, and to me SMS looks like a good idea because it’s actually a separate device, ie. “something I have”. An impostor would have to take _both_ my desktop _and_ my phone to succeed.

---

## Post 16 by @Securely0845 — 2025-06-20T19:30:28Z

The problem with SMS is SIM swapping, if someone can successfully take over your phone number or have your messages redirected then that “something you have” in your security model is useless, I’ll agree that SMS authentication is better than nothing and a lot of phone providers have started to add Number Locking, but SMS is not a secure method for sending codes and should be avoided if possible.

I’m not following on your desktop in your example, are you saying you only have local accounts and don’t use anything that has online portals? and or aren’t connected to the internet? the infostealers mentioned in the articles can easily compromise a local desktop or other device, attackers wouldn’t need physical access to it.

---

## Post 17 by @jonah — 2025-06-21T05:50:13Z

This whole story is indeed fake news:

> [@Securely0845](#):
>
> the Cybernews article that claims

“CyberNews” is AI generated lol

---

## Post 18 by @nobrowser — 2025-06-23T04:14:07Z

Hmm, if an attacker can get the kind of personal information which the carrier will ask before they port the number … I’m in deep do-do, and my online accounts are the least of my worries. Anytime I tried to change anything about the phone account, it was a total nightmare, and now thanks to you I know why :tongue: . But yes, I guess there is the possibility of a dishonest or phished employee. I’ll keep thinking about this.

---

## Post 19 by @Breeze7846 — 2025-06-25T19:29:47Z

Wait what? This whole thing is a complete nothing burger?
