Mother of All Breaches (MOAB): What Happened to the 26 Billion Leaked Records


In January 2024, cybersecurity researcher Bob Dyachenko and the Cybernews team discovered a 12-terabyte database containing more than 26 billion records. Compiled from roughly 3,800 earlier breaches and leaks, including LinkedIn, Twitter, Adobe, Dropbox, and Canva, the find was named the Mother of All Breaches, or MOAB. It is not a new hack but a reindexed collection of previously stolen credentials and personal data, and it remains the largest aggregate breach on record.
Because MOAB pulls from thousands of sources at once, most organizations can't tell at a glance whether their users or employees were exposed.
Proven Data's 24/7 Incident Response (DFIR) team helps businesses scope credential exposure like this and contain the fallout before it turns into account takeover or a ransomware incident.
What data was exposed
Each MOAB folder corresponds to a breach at an individual company, not a single new attack. According to TrendMicro's analysis, the largest contributors include:
- Tencent QQ: 1.4 billion records
- Weibo: 504 million records
- MySpace: 360 million records
- Twitter/X: 281 million records
- LinkedIn: 251 million records
- Adobe: 153 million records
This list isn't exhaustive, and duplicate records across the compiled breaches make the true number of unique individuals affected difficult to pin down.
Is MOAB still the largest data breach in 2026?
Yes, by record count. Two larger single-year events have surfaced since 2024: a 16-billion-credential compilation discovered in June 2025, and a 24-billion-record credential database found exposed in June 2026. Neither has matched MOAB's 26 billion.
| Breach | Year | Records | Type |
|---|---|---|---|
| Mother of All Breaches (MOAB) | 2024 | 26 billion | Compiled leak |
| Elasticsearch credential leak | 2026 | 24 billion | Compiled leak |
| Global credential compilation | 2025 | 16 billion | Compiled leak |
| Yahoo | 2013 | 3 billion accounts | Single company |
| National Public Data | 2024 | 2.9 billion | Data broker |
For a breakdown of last year's largest single-incident breaches, see Proven Data's analysis of 2025's biggest data breaches.
What to do if your data was exposed
Start by checking whether your information is in the dataset.
1. Change and strengthen your passwords
Run your primary work and personal emails through a breach lookup tool (such as Have I Been Pwned). If any match, update those passwords immediately, prioritizing your primary email, banking, and social platforms. Never reuse the same password across multiple accounts. A password manager makes this easier to maintain.
2. Enable multi-factor authentication
MFA adds a second verification step, like a code sent to your phone, so a leaked password alone isn't enough to log in.
3. Monitor your accounts and consider a credit freeze
Watch bank and credit card statements for unfamiliar activity, and check your credit reports with Equifax, Experian, and TransUnion. A credit freeze blocks new accounts from being opened in your name until you lift it.
4. Watch for phishing attempts
Breach data fuels convincing phishing scams that pose as your bank or a familiar service. Don't click links or share credentials in response to unsolicited messages, and verify requests through a separate channel first.
How Proven Data helps after a large-scale breach
If MOAB exposure has led to compromised accounts, credential stuffing attempts, or a downstream incident inside your organization, Proven Data's team can investigate scope, contain active threats, and help with post-breach remediation and notification requirements. Our emergency breach response engagements are built for exactly this kind of fast-moving, multi-source exposure.

Written by
Content strategist at Proven Data focused on cybersecurity education, threat analysis, and ransomware awareness.

Reviewed by
Cybersecurity writer at Proven Data covering ransomware trends, incident response, and data protection best practices.





