| Year | Researcher(s) | Compromised Records | Details | | :--- | :--- | :--- | :--- | | 2019 | UpGuard | 540+ million | Exposed records from Facebook users via third-party apps. | | 2019 | Brian Krebs | 200-600 million | Facebook users’ passwords were logged in unencrypted text files. | | 2025 | Jeremiah Fowler | 184+ million | Credentials for Google, Apple, Facebook, banks & governments. | | 2025 | Cybernews | 16+ billion | The largest known leak; a compilation of years of infostealer logs. |
: Use a unique, complex password for your Facebook account. A strong password should include a mix of uppercase and lowercase letters, numbers, and special characters. Avoid using easily guessable information such as your name, birthdate, or common words.
What is Google Dorking/Hacking | Techniques & Examples - Imperva username password -facebook.com filetype.txt
Even if someone discovers your username and password, 2FA provides a second layer of security (like a code sent to your phone), making the stolen credentials useless on their own. 3. Secure Your Servers (For Developers/IT)
In 2019, between 200 million and 600 million Facebook users likely had their account passwords logged in unencrypted text files, which were searchable by thousands of Facebook employees. | Year | Researcher(s) | Compromised Records |
Systems may log logins and passwords into a text file for debugging purposes and forget to delete them. The Risks of Leaked Credentials
Organizations must take proactive steps to ensure their sensitive credential files are never exposed to public search indexes. 1. Implement Proper Robots.txt Configurations | | 2025 | Cybernews | 16+ billion
It's a good practice to change your passwords periodically, especially if you suspect your account may have been compromised.
Never rely on "security through obscurity." Just because a .txt file has a random name does not mean a crawler won't find it via a random link. Protect all sensitive directories with robust password authentication (like HTACCESS) or keep them entirely out of the public web root. 4. Monitor with Google Search Console
If you forgot your password: