Researchers revealed what might be the biggest collection of stolen login credentials ever gathered in one location sometime in the middle of 2025. A compiled dataset, organized and searchable, contains about 16 billion records, including usernames, passwords, account details scraped from infostealer malware, phishing operations, and years of accumulated breach archives, covering accounts across Google, Apple, Meta, and dozens of other platforms. There was no significant zero-day exploit. No advanced nation-state assault. Just the patient, quiet harvesting of a system that was based on shared secrets and never sufficiently considered what would happen if those secrets were no longer kept secret. It wasn’t a particularly bad password. It failed gradually at first, then all at once, much like a slow leak eventually floods a basement.


More

Cyber Insider: ExpressVPN adds passkeys on password manager, passes security audit

ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support,…

Read More →

Tech Radar Pro: Know your agent: building the foundation of autonomous commerce

Artificial intelligence has officially entered its execution phase. After years of experimentation, businesses are rapidly deploying…

Read More →

PaymentsJournal: EMVCo Proposes Standards for Stronger Payment Authentication

EMVCo has released a draft framework that could pave the way for a universal standard…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.