A Record-Breaking Exposure: 24 Billion Credentials Found Unprotected

In June 2026, security researchers stumbled on something that put nearly every other data leak of the year in perspective: a publicly accessible database containing more than 24 billion stolen credential records. There was no password, no login wall, and no encryption standing between the internet and the data. Anyone who found the exposed server could have browsed it freely.

To be clear, 24 billion records does not mean 24 billion unique people. Databases like this are typically compilations, credential sets scraped and combined from years of previous breaches, malware logs, and leaked password dumps, all aggregated into one massive file. Duplicate entries are common, and the same email address might show up dozens of times paired with different passwords stolen at different points in time. Still, the sheer scale of the exposure illustrates a problem that has become routine in 2026: enormous troves of previously stolen data keep resurfacing, unsecured, in new locations.

This kind of exposure is particularly dangerous because it lowers the barrier to entry for cybercriminals. Instead of paying for access to a curated breach dataset on a dark web forum, attackers can simply pull credentials from an open database and start testing them against banking sites, email providers, and corporate logins through automated "credential stuffing" attacks.

Kodak Joins the List of 2026 Breach Victims

The same month brought a second, more targeted incident. Kodak confirmed a breach after a hacking group claimed to have stolen roughly 2.2 million customer and corporate records. The group listed Kodak on a dark web leak site, a tactic that has become standard practice for extortion-focused hacking crews looking to pressure a company into paying before the stolen data is published or sold.

This approach mirrors what's played out at other organizations throughout the year. Groups like CMD have taken the extortion playbook further by auctioning stolen data outright rather than simply threatening to leak it, while DARK PROJECT has used its leak site to name multiple victims at once as a way of maximizing pressure. Whether or not Kodak's attackers followed through on their threat to publish the full dataset, the pattern is the same: steal first, then use public exposure as leverage.

Part of a Larger Pattern in 2026

Neither the 24 billion credential exposure nor the Kodak breach happened in isolation. 2026 has seen a steady drumbeat of large-scale incidents across sectors and geographies. Government systems haven't been spared either; UK and Swiss government breaches disrupted operations in early August, showing that public sector organizations face the same exposure risks as private companies. On the consumer side, a lawsuit filed over a June breach alleges that as many as 2.4 billion TikTok users had their data exposed, a claim that, if accurate, would rank among the largest breaches ever reported.

What ties these incidents together isn't a single cause, but a shared set of underlying weaknesses: unsecured databases left open to the internet, credentials reused across services, and attackers who increasingly treat stolen data as a commodity to be auctioned, leaked, or ransomed rather than simply hoarded.

What This Means For You

Most people will never know for certain whether their specific credentials sat inside that 24-billion-record database, and Kodak has not published a full list of who was affected by its breach. That uncertainty is part of why 2026 data leaks matter to ordinary users, not just IT departments. If your email and password combination has appeared in any previous breach, and there have been many, there's a real chance it's part of a larger aggregated dataset circulating right now.

The practical response doesn't require panic. It requires basic hygiene that closes off the most common attack paths: unique passwords per account, multi-factor authentication wherever it's offered, and periodic checks of whether your email address has turned up in known breaches.

Actionable Takeaways

  • Use a password manager to generate and store unique passwords for every account, so a leaked credential from one breach can't unlock others.
  • Enable multi-factor authentication on email, banking, and any account holding sensitive personal or financial information.
  • Check breach-monitoring services periodically to see if your email address has appeared in a known leak, including large aggregated databases like the one discovered in June.
  • Treat any unexpected password reset emails or login alerts as a signal to change your password immediately, even if you can't confirm which breach triggered them.
  • Stay informed about ongoing 2026 data leaks affecting companies you do business with, since breach notifications often arrive weeks or months after the actual incident.

Data leaks at this scale are unlikely to slow down in 2026. Staying ahead of them isn't about avoiding every risk, it's about making sure that when a leak happens, it doesn't turn into a compromised account or stolen identity.