A massive global data breach has compromised more than 184 million unique credentials, including usernames, passwords, and email addresses linked to major platforms such as Google, Microsoft, Apple, Facebook, Instagram, and Snapchat, as well as government portals, banking systems, and healthcare platforms. The National Computer Emergency Response Team (NCERT) of Pakistan has issued an advisory warning that the exposed information, collected via info-stealing malware, was left in an unencrypted, publicly accessible database online. According to the NCERT, the exposed data was not protected by any form of encryption or access control, making it highly vulnerable. The leak includes sensitive login information collected from infected systems through malware, which silently harvested data from users’ devices. No user interaction was needed for the credentials to be compromised, and the leaked database requires no privileges or authentication for access. Cybersecurity experts warn that this breach could enable credential stuffing attacks, where automated systems attempt logins using stolen usernames and passwords across multiple services. The breach also heightens the risk of account takeovers, identity theft, targeted phishing attacks, and even ransomware deployment on individual and enterprise systems. Critical government platforms and sensitive sectors are also at risk of exploitation. NCERT recommends immediate action to
Read More










