Moneycontrol PRO
HomeTechnologyMassive data breach alert: 184 million passwords leaked; Apple, Google, Instagram, Microsoft logins exposed, here’s what you should do

Massive data breach alert: 184 million passwords leaked; Apple, Google, Instagram, Microsoft logins exposed, here’s what you should do

A massive breach exposed 184 million passwords, affecting Apple, Google, Microsoft, Facebook, and more.

June 03, 2025 / 16:04 IST
Data breach

A massive data breach has exposed over 184 million user records, including plain-text email addresses, passwords, and direct login URLs — raising serious cybersecurity concerns for millions of Americans. The unprotected database, discovered by cybersecurity researcher Jeremiah Fowler, was found publicly accessible online and reportedly contained sensitive information linked to major brands such as Apple, Google, Facebook, Microsoft, and several banking and government services.

Tech giants impacted: Apple, Google, Meta, Microsoft
While the database wasn’t hosted by any one company, analysis of the leaked records revealed credentials and login links connected to a range of platforms:
Apple iCloud and iTunes accounts

Google services, including Gmail, Drive, and Google Workspace
Meta’s Facebook and Instagram logins
Microsoft Outlook, Office 365, and Teams
Banking portals, crypto wallets, and government service platforms

Fowler emphasised that the data leak included direct login URLs, which in some cases could bypass the traditional password entry process, making it even easier for hackers to access private user accounts.

Why is this breach different?
Unlike many earlier breaches where passwords were hashed or encrypted, this leak involved plain-text passwords, making the stolen data immediately usable for cybercriminals. The inclusion of one-click login links further elevates the risk by allowing potential attackers to log in to accounts without entering a password.

The breach is being described as a “cybercriminal’s working list,” offering tools ready for phishing, identity theft, credential stuffing attacks, and unauthorised financial transactions.

Cloud misconfigurations to blame
The unsecured database appears to have been hosted on a cloud platform — likely AWS, Google Cloud, or Microsoft Azure — and was left open due to misconfigured security settings. An IBM report recently highlighted that 82% of all data breaches over the past year involved cloud environments, often due to poor access controls or exposed public buckets.

What you should do
Security experts urge users to:
Change all passwords immediately
Use multi-factor authentication (MFA)
Freeze your credit via Equifax, Experian, and TransUnion
Use tools like Google Password Checkup or HaveIBeenPwned.com to check for exposure
Set real-time alerts on banking and credit accounts

Invite your friends and family to sign up for MC Tech 3, our daily newsletter that breaks down the biggest tech and startup stories of the day

MC Tech Desk Read the latest and trending tech news—stay updated on AI, gadgets, cybersecurity, software updates, smartphones, blockchain, space tech, and the future of innovation.
first published: Jun 3, 2025 04:03 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347