In October 2025, cybersecurity researchers verified a massive public leak exposing 183 million email and plaintext password combinations online. Research confirmed that the dataset originated from widespread infostealer malware infections on endpoint devices — not a breach of Google’s server infrastructure.
| Category | Incident Details |
|---|---|
| Total Records | 183 Million email + password pairs |
| Root Source | Infostealer malware infections (RedLine, Raccoon 2.0, Vidar) on endpoint devices |
| Data Format | Plaintext credentials & browser autofill logs |
| Credential Age | ≈ 8% New / Active (≈ 16 Million) | 92% Previously Leaked / Historical |
| Geographic Scope | Global (US, India, EU regions, Middle East) |
| Infrastructure Status | Google Core Systems confirmed secure and uncompromised |
The dataset was compiled from endpoint infections driven by trojanized software, pirated downloads, and phishing lures carrying malware families like RedLine Stealer, Raccoon Stealer, and Vidar. Once executed on a host, these stealer payloads harvest plaintext credentials, session tokens, and saved passwords directly from browser vaults before exfiltrating them to command-and-control (C2) servers.
Because passwords were recycled across multiple personal and corporate services, the primary risk involves automated credential-stuffing and targeted business email compromise (BEC) attacks against organizational perimeters.
Staarken Infosec provides enterprise VAPT, compromise assessments, and security awareness campaigns to defend your perimeter against endpoint stealers.