Researchers revealed what might be the biggest collection of stolen login credentials ever gathered in one location sometime in the middle of 2025. A compiled dataset, organized and searchable, contains about 16 billion records, including usernames, passwords, account details scraped from infostealer malware, phishing operations, and years of accumulated breach archives, covering accounts across Google, Apple, Meta, and dozens of other platforms. There was no significant zero-day exploit. No advanced nation-state assault. Just the patient, quiet harvesting of a system that was based on shared secrets and never sufficiently considered what would happen if those secrets were no longer kept secret. It wasn’t a particularly bad password. It failed gradually at first, then all at once, much like a slow leak eventually floods a basement.


More

IoT News: WBA and FIDO test zero-touch IoT Wi-Fi onboarding

Industrial operators can automate IoT onboarding across Wi-Fi networks through a joint specification from the Wireless…

Read More →

Tech Times: Visa Payment Passkey Goes Live at Five India State Banks: OTP Attack Surface Eliminated

India’s five-decade-old authentication habit — waiting for a six-digit code on a phone — got…

Read More →

FinTech Futures: Sibos 2026: Digital finance in an AI-driven economy – when the agent does the buying, who owns the customer?

By shaping the standards of identity, control, and compliance today, financial institutions can ensure they…

Read More →


123…339 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.