10,000 databases with more than 10 billion credentials exposed
John E. Kaye
- Published
- News, Technology

Recently, researchers have identified a total of 9,517 unsecured databases containing 10,463,315,645 entries with such data as emails, passwords, and phone numbers.
The databases were found across 20 different countries, with China being at the top of the list — the country had nearly 4,000 exposed databases. This means that potentially more than 2.6 billion users could have had their accounts breached.
The United States comes second, with nearly 3,000 unsecured databases and almost 2.3 billion entries made available online.
India was third, with 520 unsecured databases and 4,878,723 entries.
Sensitive vs testing data
While some of this data might be useless and only used for testing, much of it could be damaging if exposed. Some of the largest data leaks of last year resulted from exposed databases. For example, millions of Facebook records were exposed on a public Amazon server. In another incident, an unsecured database exposed information of 80 million US households. The data included victims’ addresses, income, and marital status. A rehabilitation clinic in the US also suffered from a data leak, over which nearly 150,000 patients had their personal information exposed. The most worrying part is that this data was not leaked by a persevering hacker — it was simply sitting there in a public database. .
Low-skilled job
While the idea of searching for exposed databases may seem complex, the process itself is quite straightforward. Search engines like Censys or Shodan scan the web constantly and let anyone view open databases in just a few clicks. If the database managers used the default logins, getting into one would be a piece of cake.
“In fact, with proper equipment, you could easily scan the whole internet on your own in just 40 minutes,” says Chad Hammond, security expert at NordPass.
The essentials of database security
Data security and protection should be a top priority. “Every company, entity, or developer should make sure they never leave any database exposed, as this is obviously a huge threat to user data,” says Chad Hammond.
When asked to highlight the main points of database security, the expert emphasised:
“Proper protection should include data encryption at rest, wire (in motion) data encryption, identity management, and vulnerability management.
Data can be exposed to risks both in transit and at rest and therefore requires protection in both states. While there are several different approaches, encryption plays a major role in data protection and is a popular tool for securing data both in transit and at rest.
Nevertheless, all data should be encrypted using trusted and robust algorithms instead of custom or random methods. It’s also important to select appropriate key lengths to protect your system from attacks.
Identity management is another important step and should be used to ensure that only the relevant people in an enterprise have access to technological resources.
Finally, every company should have a local security team responsible for vulnerability management and able to detect any vulnerabilities early on,” says Chad Hammond.
As for the users, the security expert yet again draws attention to the importance of a strong password. “The fact that we have more than 10 billion passwords up for grabs should only encourage people to think of strong, lengthy passwords. If your password is “12345”, no firewall in the world will protect your data. Your password shouldn’t be a dictionary word either — an average person uses only about 20,000-30,000 words, so chances are that all of them are already among those 10 billion,” says the NordPass security expert.
Methodology: NordPass partnered up with a white hat hacker, who scanned elastic search and mongoDB libraries, looking for exposed, unprotected databases. Once found, he logged into those public databases and checked what kind of data could be found there. The white hat hacker has shared with NordPass how many exposed databases and entries he had found. The hacker requested to stay anonymous. Time frame: June 2019 to June 2020.

For more information visit: nordpass.com
For more Technology and Daily news follow The European Magazine
RECENT ARTICLES
-
MINI at 25 – the numbers behind the Oxford-built icon -
More than half of employers say they cannot find graduates with the right AI skills, study finds -
Stratospheric telecoms blimp completes “historic” record 12-day flight over Atlantic -
MICE market forecast to reach $2.3tn by 2032, report says -
Mobile operators warn of higher bills and slower 5G rollout after energy support exclusion -
Lufthansa cuts 20,000 summer flights as Iran war drives up fuel costs -
People act more rationally when they think they are dealing with AI, study finds -
Toxic bosses may thrive at work, but the office pays the price, new research finds -
Europe launches ‘anti-kill switch’ cloud shield as Trump fears grip Brussels -
Starmer summons social media chiefs to Downing Street over child safety -
The European Spring 2026 edition – out now -
Inside Qantas’ new ultra-long-haul A350s with stretch zone, jet lag lighting and fewer seats -
Landmark UK nuclear deal to cut reliance on foreign energy after Middle East tensions -
Breitling launches £9,500 Artemis II watch as Moon crew returns to Earth -
Ivy and Annabel’s owner agrees £1.4bn sale of hospitality empire to Abu Dhabi-backed buyer -
Orbán concedes defeat as Péter Magyar heads for sweeping Hungary election victory -
UAE unveils plans for major new military rescue training centre -
Electric air taxis move closer after aircraft completes key in-flight switch -
World’s largest cruise ship revealed with nine pools, 28 places to eat and giant waterpark -
Artemis II crew break Apollo 13 record for farthest human spaceflight -
Starmer uses Easter message to stress hope, service and national renewal -
‘Houston, we have a problem’: astronauts fix loo aboard Artemis II -
EU moves to make Europe’s tinderbox landscapes less prone to wildfire -
Artemis II lifts off for Moon mission – here is what the astronauts will be doing day by day -
GITEX Africa Morocco to host 1,450 exhibitors and startups as Marrakech event sharpens focus on AI and digital sovereignty



























