What 135 Million Exposed Accounts Really Tells Us
06 July 2026A total of 28 breach events were found and analysed resulting in 135,544,522 exposed accounts containing a total of 40 different data types of personal datum. The breaches found publicly and freely available included Indonesia Person Dump, ULP Alien Txt File - Episode 40, Portal de Servicios en Línea del Poder Judicial de la Federación (PJF), eBay Marketplace and Combo List [7]. Sign in to view the full
library of breach events which includes, where available, reference articles relating to
each breach.
Categories of Personal Data Discovered
Contact, Digital Behaviour, Technology, Sociodemographic, Commerce, Geolocation, Academic, Relationships, National Identifiers, Career, Legal, Unstructured, Finance, Audio and Visual.
The signal this week
The 28 breach events analysed this week contained 135,544,522 exposed accounts and 40 distinct types of personal data. That is a substantial volume, but it requires careful interpretation. Several of the selected events are compiled collections rather than conventional breaches attributed to a single organisation. Their records may have originated at different times, appeared in previous collections or overlapped with other material.An exposed-account total therefore measures the records found and analysed. It does not automatically represent the same number of unique people, newly compromised accounts or currently usable credentials.
This distinction does not make the material unimportant. It changes the questions a defensive team should ask.
What the selected breaches tell us
The selected breaches include broad personal-data collections, credential compilations, a public-sector service and a global marketplace:- Indonesia Person Dump is a broad collection of personal records associated with individuals in Indonesia.
- ULP Alien Txt File – Episode 40 is a credential-oriented collection containing URL, login and password records.
- The Portal de Servicios en Línea del Poder Judicial de la Federación is the online-services portal for Mexico’s federal judiciary.
- eBay Marketplace connects buyers and sellers through a global ecommerce platform.
- Combo List [7] is a compiled collection of username or email and password combinations.
The BreachAware team has recorded and reviewed the provenance of this material. The descriptions shared here are intentionally limited, providing defenders with relevant context without publishing source locations, detailed contents or information that could encourage misuse.
The numbered labels attached to the ULP and combo-list collections describe how the material was packaged and catalogued. They should not be interpreted as the dates on which every original account was exposed.
Mexico’s federal judiciary portal supports activities including submitting legal documents, receiving electronic notifications and consulting electronic case files. eBay operates a marketplace connecting individual buyers, sellers and businesses across many countries. These are very different environments from compiled credential collections, even though records from each contribute to the week’s overall account total.
[Mexico’s federal judiciary describes the functions available through its online-services portal](https://www.serviciosenlinea.pjf.gob.mx/juicioenlinea/). [eBay describes its marketplace as connecting millions of buyers and sellers internationally](https://www.ebayinc.com/our-company/who-we-are/).
Why a record is not necessarily a new victim
Large account totals can combine several different concepts:- One person may have more than one account.
- The same email address may appear in multiple events or collections.
- A credential may have been exposed previously and subsequently republished.
- Some records may relate to closed or abandoned accounts.
- Passwords may have been changed since the original exposure.
- A dataset may combine records originating from different services and periods.
Without deduplication and historical comparison, these categories cannot be converted into a reliable count of unique affected people.
Compiled credential collections are especially likely to require this distinction. Their purpose is to bring account identifiers and passwords into a consistent format, but the presence of a credential does not establish that it remains valid.
The defensive relevance depends on whether the identity is current, the password has been reused, the account provides meaningful access and additional authentication controls are in place.
The UK National Cyber Security Centre explains that credential stuffing uses username and password combinations obtained from one service against other services where the same password may have been reused. [NCSC credential-stuffing guidance](https://www.ncsc.gov.uk/news/use-credential-stuffing-tools).
This is why a repeated historical record can still matter. It may not represent a newly compromised person, but it can identify a password that remains in use elsewhere or an account that was never remediated.
How security teams should read a large total
A headline account figure is useful for describing processing scale, but it is not a response priority on its own. Defenders need several additional measures:- How many identifiers are unique after normalisation?
- How many relate to current employees, customers or suppliers?
- Which records contain authentication data?
- Which passwords or identifiers have appeared previously?
- Are any affected accounts privileged or business-critical?
- Does the material contain recent session or device information?
- Which exposures require notification, investigation or monitoring?
These questions separate volume from operational relevance. They also prevent teams from spending equal effort on a duplicate historical record and a current credential associated with sensitive access.
Three defensive checks
1.Separate record volume from unique identity count. Normalise email addresses and other identifiers, identify duplicates and retain links to the original provenance. Report total records, unique identifiers and newly observed records as separate measures.2.
Assess credentials without attempting to replay them. Compare exposed identities through authorised breach-monitoring and internal security processes. Block known compromised passwords, review authentication logs and require resets where the evidence supports action. Do not test credentials by attempting to sign in to third-party accounts.3.
Prioritise current access and business impact. Give greater attention to active employees, privileged users, administrative portals and accounts connected to sensitive services. A smaller set of current, high-impact identities may deserve a faster response than a much larger historical collection.Perspective
The 135,544,522 exposed accounts found this week should not be described as 135,544,522 newly breached people. The material may contain duplicate, historical, republished or overlapping records, particularly within compiled credential collections.The 40 data types describe the variety found across all 28 events. They were not necessarily present in every event or account.
The selected examples also do not demonstrate that ecommerce, public-sector services or Indonesian individuals are being targeted more heavily than other groups. They are not a representative sample from which to calculate a geographic or industry trend.
The useful conclusion is that very large exposure totals require more analysis, not more dramatic language. Deduplication, recency, credential validity, account status and business relevance determine what the number means for a particular organisation.
BreachAware does not publish source locations, complete breach inventories or unnecessary operational details that could facilitate misuse.