Researchers revealed what might be the biggest collection of stolen login credentials ever gathered in one location sometime in the middle of 2025. A compiled dataset, organized and searchable, contains about 16 billion records, including usernames, passwords, account details scraped from infostealer malware, phishing operations, and years of accumulated breach archives, covering accounts across Google, Apple, Meta, and dozens of other platforms. There was no significant zero-day exploit. No advanced nation-state assault. Just the patient, quiet harvesting of a system that was based on shared secrets and never sufficiently considered what would happen if those secrets were no longer kept secret. It wasn’t a particularly bad password. It failed gradually at first, then all at once, much like a slow leak eventually floods a basement.


More

Biometric Update: Singapore expands Singpass passkeys to Android users

Singapore’s digital identity system Singpass has added passkey login to Android devices, the Government Technology…

Read More →

Fintech Global: EMVCo drafts framework for agentic card payments

The EMV Agentic Payments – Framework for Specifications has been developed by EMVCo’s newly formed…

Read More →

FinAINews: Podcast | Mastercard focuses on ‘Verifiable Intent’ for agentic payments, CDO says

Nearly a year after launching Agent Pay, Mastercard is focused on developing trust to drive adoption.  “The…

Read More →


123336 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.