Threat Intelligence

🔴 184 Million Passwords Exposed in Unsecured DB — Act Now

By Ateeq Y Tanoli, BestPasswordGenerator.org · 24 May 2026 · 9 min read · 1,811 words

Here is the short version: cybersecurity researcher Jeremiah Fowler discovered a publicly exposed database containing 184 million login credentials — in plaintext, with no password protection whatsoever. The database included passwords for Google, Facebook, Microsoft, Apple, Netflix, PayPal, Amazon, and even bank accounts and government email addresses from 29 countries. If you have an online account, there is a real chance your credentials are in this dataset. Here is exactly what happened, how to check if you are affected, and what to do right now to lock down your accounts.

On May 22, 2026, news broke that Fowler — the same security researcher who uncovered the January 2026 database of 149 million exposed credentials — had found what he called "one of the weirdest" databases of his career. The Elasticsearch database, spanning over 47 GB and containing 184,162,718 records, was sitting on an unmanaged server with zero security. It had no authentication, no encryption, and no owner that would claim it.

Fowler described the find as "a cybercriminal's dream working list." He was not exaggerating.

What the 184 Million Password Database Contained

The database stored plaintext account IDs, URLs, usernames, and — most critically — passwords labelled with the field name "Senha" (Portuguese for "password"). Fowler analysed a sample of just 10,000 records and found credentials from an alarming breadth of services:

Even more concerning: the sample contained 220 email addresses with .gov domains across at least 29 countries, including the United States, Australia, Canada, China, India, Israel, New Zealand, Saudi Arabia, and the United Kingdom. Fowler also found keywords like "bank" appearing 187 times and "wallet" occurring 57 times in the credential records.

To verify the data was genuine, Fowler contacted some of the exposed email address holders — and received confirmations that their accounts were indeed compromised.

Where Did These 184 Million Passwords Come From?

The database showed strong signs of having been compiled by infostealer malware — a type of malicious software that silently extracts saved credentials from browsers, email clients, and messaging apps. Two common families, Lumma Stealer and RedLine, are known for exactly this type of large-scale credential harvesting.

Infostealer infections typically spread through:

The database was hosted by World Host Group (WHG). When WIRED contacted WHG after Fowler's report, CEO Seb de Lemos confirmed the server was "unmanaged and fully controlled by a fraudulent user" who had also uploaded illegal content. The company shut down the server and said it would cooperate with law enforcement.

What makes this breach especially dangerous is not just the scale — it is the freshness. Many of these credentials were harvested recently, meaning the accounts are likely still active and the passwords may still work. The researcher who generates and tests passwords professionally can confirm: a credential that is 48 hours old is still valuable to an attacker.

Why 184 Million Plaintext Passwords Matter More Than Breach Size Alone

It is tempting to focus on the raw number — 184 million is big but not the biggest we have seen. The Specops Software 2026 report documented 6 billion passwords stolen by malware in 2025 alone. But this database is different for three reasons:

1. The data was in plaintext. No hashing, no salting, no encryption. Anyone who accessed the database could read every password immediately. There was no cracking required — no GPU cluster, no hash table, no waiting.

2. It was structured for targeting. The Elasticsearch database contained indexed metadata with reversed host paths, making it trivial for anyone with access to run queries like "give me all Gmail accounts" or "show me only .gov emails." This is not a raw dump — it is a searchable arsenal.

3. It was online and accessible. Unlike a dark-web forum post that requires technical know-how to access, this database was visible to anyone on the internet who knew where to look. Fowler found it through routine scanning. The window of exposure was at least several weeks.

According to Fowler, "Even if one account is still active and they gain unauthorised access, it could create serious security risks and open the door to a wide range of potential attacks."

What Attackers Can Do With 184 Million Credentials

The moment a credential database like this becomes public, attackers begin working through it systematically. Here is what happens next:

Credential stuffing. Automated bots test every username and password pair against dozens of other websites. If you reused your Facebook password on your bank, your bank account is now in play. Credential stuffing attacks surged more than 1,200% in 2026 precisely because breach databases like this one keep feeding attackers fresh credentials.

Account takeover. Once an attacker controls your email, they can reset passwords for every other service you use. PayPal, Amazon, banking — a single email compromise cascades into total account takeover.

Targeted phishing. With your email address, the services you use, and often your real name from the credential dump, attackers can craft highly convincing phishing emails that appear to come from services you trust.

Dark web distribution. The data will be copied, repackaged, and sold on Telegram channels and dark-web marketplaces. It will fuel attacks for months or years.

How to Check if Your Passwords Were in the 184 Million Leak

Here is the step-by-step process to find out if your accounts are affected:

  1. Go to Have I Been Pwned (HIBP) at haveibeenpwned.com and enter your primary email address. This is the free, authoritative breach-checking service run by security researcher Troy Hunt.
  2. Check every email address you use. Most people have at least three: work, personal, and a "junk" email for newsletters. Check all of them.
  3. Run our free password generator to create strong, unique replacement passwords immediately.
  4. Check your password manager's breach monitoring. If you use Bitwarden or 1Password, both have built-in breach detection that cross-references your saved credentials against known leaks.
  5. Pay special attention to financial accounts. Any bank, PayPal, or cryptocurrency service you use should have its password changed immediately, even if your email does not appear in HIBP yet.

What to Do Right Now: Lock Down Your Accounts in 5 Steps

Step 1: Change every reused password immediately. If you use the same password on more than one site, change every instance. Attackers count on password reuse — it is what makes credential stuffing profitable. Your new passwords should be at least 16 characters long with a mix of letters, numbers, and symbols — exactly what our password generator creates.

Step 2: Enable multi-factor authentication on every account that supports it. Microsoft research found that MFA blocks 99.9% of automated account attacks. Even if an attacker has your password, a second authentication factor stops them cold. See our complete MFA setup guide.

Step 3: Install antivirus and antimalware protection. Since this credential database was likely collected by infostealer malware, protecting your devices from future infections is critical. Kaspersky Antivirus provides real-time protection against infostealers, ransomware, and phishing attempts. A good antivirus suite catches infostealer malware before it can exfiltrate your credentials.

Step 4: Run a full password security audit. Our personal password security audit guide walks through every stage — from cataloguing your accounts to rotating passwords and locking down weak spots. Do this annually at minimum, but after a breach of this size, do it today.

Step 5: Use a VPN on public Wi-Fi. Infostealer infections often spread over unsecured networks. When working from coffee shops, airports, or hotels, Hide My Name VPN offers a no-logs policy that encrypts your connection and prevents attackers on the same network from intercepting your traffic.

Step 6: Monitor your accounts for suspicious activity. Enable login notifications on your email, social media, and financial accounts. Many services now offer real-time alerts when a new device logs in. Do not dismiss these — if you get a login alert you did not trigger, act immediately.

FAQs: 184 Million Password Breach

Was my password in this 184 million database?

You can check by entering your email address at haveibeenpwned.com. However, breach databases take time to be indexed — if you were affected, it may take days or weeks for your credentials to appear in HIBP. Change your passwords proactively rather than waiting for a notification.

Should I still use a password manager after this breach?

Yes. This breach was not caused by a password manager — it was caused by infostealer malware harvesting credentials from browsers and devices. A password manager like Bitwarden or 1Password actually protects you by generating unique, complex passwords for every site, so even if one is stolen, the rest of your accounts remain safe.

Is changing my password enough to protect my accounts?

Changing passwords is a critical first step, but it is not sufficient on its own. You should also enable MFA on every account, install antimalware protection, and check your browser extensions for anything suspicious. Attackers who already have access to your device can steal your new password just as easily as the old one.

Who was responsible for this database?

The owner of the database is unknown. World Host Group confirmed the server was controlled by a fraudulent user who had also uploaded illegal content, but the company has not disclosed the customer's identity. Security researcher Jeremiah Fowler suspects the data was compiled by operators of infostealer malware campaigns.

How can I protect myself from infostealer malware in the future?

Only download software from official sources, avoid cracked or pirated software, do not click suspicious email attachments, keep your operating system and browser updated, and run reputable security software.

Bottom Line: Treat Every Breach Like It Affects You

The 184 million password database is the latest reminder that credential theft is not slowing down. Between the 149 million credentials Fowler found in January, the 6 billion passwords stolen by malware in 2025, and the 1,200% surge in credential stuffing attacks, one truth is clear: your passwords will be compromised eventually. The goal is not to prevent every breach — that is impossible. The goal is to ensure that a single compromised password does not lead to a cascade of account takeovers.

Use a password manager. Enable MFA everywhere. Generate strong, unique passwords for every account. Run a full password security audit today. And when you see a breach headline like this one, act — do not scroll past it.

This page contains affiliate links. If you purchase through these links, we may earn a commission at no extra cost to you.

Generate a Free Strong Password →

More Password Security Tools

🔑 SecureKeyGen⚔️ TitanPasswords🔐 Free Strong Password⚡ Instant Password🗝️ Iron Vault Keys🔑 Random Pwd Tool👨‍👩‍👧‍👦 Safe Pass Builder🛡️ Trusty Password⚙️ StrongPassFactory🔑 SecureKeyGen.org📚 TrustyPassword.org
We use cookies to improve your experience. Learn more

🛡️ Security Picks This Week

Hand-picked security tools — updated weekly.

Thetis Pro-C FIDO2 Key

Thetis Pro-C FIDO2 Key

Budget USB-C/NFC security key with TOTP authenticator app.

Check price →
Yubico Security Key NFC

Yubico Security Key NFC

Budget-friendly 2FA key — USB-A & NFC, FIDO2 certified.

Check price →
TP-Link ER605 VPN Router

TP-Link ER605 VPN Router

Multi-WAN VPN gateway — secure every device on your network.

Check price →

As an Amazon Associate we earn from qualifying purchases.