Unprotected Database Exposes 48M Gmail and 6.5M Instagram Records Online

A massive credential database containing 149.4 million exposed logins and passwords has been discovered in an unprotected, unencrypted cloud repository.

Cybersecurity researcher Jeremiah Fowler uncovered the breach and reported findings to ExpressVPN, revealing a sprawling collection of stolen accounts spanning major platforms, including Gmail, Instagram, Facebook, and government systems.

The raw dataset totaled 96 GB of credential data, publicly accessible without password protection or encryption.

The database indexed thousands of files containing emails, usernames, passwords, and direct login URLs, providing attackers with everything needed to launch automated credential-stuffing campaigns.

Scope of Exposed Accounts

The breach represents an unprecedented collection of infostealer malware output, capturing credentials across entertainment, financial, and social media platforms:

Email Providers (Primary Targets):

  • Gmail: 48 million accounts
  • Yahoo: 4 million accounts
  • Outlook: 1.5 million accounts
  • iCloud: 900,000 accounts
  • .edu domains: 1.4 million accounts

Major Platforms Compromised:

  • Facebook: 17 million accounts
  • Instagram: 6.5 million accounts
  • Netflix: 3.4 million accounts
  • TikTok: 780,000 accounts
  • Binance: 420,000 accounts
  • OnlyFans: 100,000 accounts

Notably, the database included credentials associated with .gov domains from multiple countries,a critical national security concern.

Government account compromise could facilitate targeted spear-phishing, network infiltration, or impersonation attacks against government infrastructure.

Analysis reveals the database stored output from advanced infostealer malware, structured using “host_reversed paths” (com.example.user.machine) to organize stolen data by victim and source.

This formatting enables efficient indexing while potentially bypassing detection rules targeting standard domain formats.

Each record included unique line hashes as document identifiers, preventing duplicates. The database was searchable via basic web browser queries requiring no authentication or specialized tools, enabling anyone to access millions of credentials instantly.

Fowler reported the discovery to the hosting provider through abuse channels but faced significant delays.

The provider initially disclaimed responsibility, stating the IP was operated by a subsidiary using the parent organization’s name.

It took nearly a month and multiple escalations before the database was finally suspended. Disturbingly, the record count increased between discovery and removal, suggesting others may have accessed the data.

The exposure creates severe risks for affected users:

  • Credential-stuffing attacks against email, financial services, and enterprise systems
  • Automated account takeovers using valid usernames and passwords
  • Identity theft and financial fraud exploit compromised banking information
  • Phishing campaigns referencing real accounts and services for increased effectiveness

Individuals should immediately enable multi-factor authentication, review login histories for suspicious activity, update passwords across all accounts, and deploy antivirus software.

Organizations must implement abuse reporting channels monitored by humans, enforce encryption standards for credential storage, and establish rapid response protocols for responsible disclosure reports.

The discovery underscores a critical paradox: cybercriminals prioritize operational speed over security, leaving valuable stolen data inadequately protected, a vulnerability that researchers continue exploiting to expose and disrupt criminal infrastructure.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories