In June 2026, researchers found a publicly exposed database sitting open on the internet containing an almost incomprehensible 24 billion records — more than 8 terabytes of usernames, email addresses, plaintext passwords, and the exact login pages they went with. It wasn’t a single company’s breach; it was a compilation, an aggregated pile assembled from countless earlier breaches and from malware that quietly steals credentials off infected computers.
Numbers this big go numb fast, so here’s the part that matters: collections like this are the fuel for account takeovers. Attackers feed them into automated tools that try every leaked email-and-password combination against banks, email providers, and shops — a technique called credential stuffing. It works for exactly one reason: people reuse passwords. If a password you used somewhere is in that pile, every other account using the same password is now at risk.
Don’t panic — but do assume you’re in it
With tens of billions of records aggregated from years of breaches, the realistic assumption for anyone who’s been online for a while is that some credential of yours is in a dump like this. That’s not cause for alarm; it’s cause for a few specific actions. Panic isn’t a plan. This is:
The five things to do
1. Check where you’ve been exposed
Use a reputable breach-notification service — Have I Been Pwned is the trusted standard — to see which of your accounts have appeared in known breaches. Enter your email addresses (including old ones). It’ll show you which sites leaked your data and roughly when. This turns a vague dread into a concrete to-do list.
2. Fix reused passwords, worst first
The danger isn’t one leaked password — it’s the same password reused across accounts. Change it everywhere it was reused, starting with the accounts that matter most: email first (it resets everything else), then banking, then anything flagged in the breach check. Give each account its own unique, random password. The only sane way to do this is a password manager — it generates and remembers them so you don’t have to.
3. Turn on two-factor authentication
Even if a password leaks, two-factor authentication (2FA) stops the attacker from getting in. Turn it on for email, banking, and your password manager at minimum. Prefer an authenticator app or a hardware key over SMS codes, which can be intercepted via SIM-swapping.
4. Adopt passkeys where they’re offered
Many major sites now support passkeys, which replace passwords with a cryptographic key tied to your device. They can’t be phished and there’s no password to leak in the next mega-dump. When a site offers one, take it — and store it in your password manager so a lost phone doesn’t lock you out.
5. Clean the malware angle
A chunk of these credentials come not from company breaches but from infostealer malware on people’s own machines — software that silently harvests saved passwords. Run a reputable malware scan, be ruthless about not installing sketchy “cracked” software and browser extensions, and keep your systems updated. A password manager doesn’t help if your computer itself is quietly reading your keystrokes.
The bigger lesson
You can’t stop companies from getting breached, and you can’t un-leak a password that’s already out there. What you can control is blast radius: unique passwords mean one leaked credential compromises exactly one account instead of twenty, and 2FA plus passkeys mean a leaked password often isn’t enough to get in at all. Do the five things above once, properly, and the next record-breaking data dump becomes a headline you read with mild interest rather than a personal emergency.
If you only do one thing today, set up a password manager and fix your email password. We keep a running eye on notable breaches and what they mean for ordinary people — the recurring theme, every single time, is that the people who set this up in advance barely have to react.