A massive data breach dubbed the ‘Mother of All Breaches’ has seen 26 BILLION records leaked from sites like Twitter, Linkedin and Dropbox – here’s how to check if you’re affected

Your personal data may have been leaked in the ‘Mother of all Breaches’ (MOAB), cybersecurity researchers warn.

More than 26 billion personal data have been exposed, which researchers say is the largest data breach ever.

Sensitive information from several sites, including Twitter, Dropbox and Linkedin, was discovered on an unsecured page.

Worryingly, the researchers who discovered the breach claim that this breach is extremely dangerous and could trigger a tsunami of cybercrime.

Here’s how to check if you’re affected.

Your personal data may have been leaked in the ‘Mother of all Breaches’, cybersecurity researchers have warned (stock image)

If you're using one of these sites, there's a good chance your data has been leaked.  While some of the data is certainly duplicate, these sites have each leaked more than 100 million personal details

If you’re using one of these sites, there’s a good chance your data has been leaked. While some of the data is certainly duplicate, these sites have each leaked more than 100 million personal details

How to check if your data has been leaked

To see if your data has been affected by historical data breaches, you can use Cybernews’ data breach check.

Simply enter your email address or phone number into the search bar and click ‘check now’ to see if that account information has been leaked.

Cybernews says it is currently working on updating the tool to ensure it can check for data leaked in this latest breach.

Alternatively, Cybernews also has one searchable list of sites affected by the breach.

If you’re particularly concerned about the impact of a site you’re using, you can search the site name to see if any data has been leaked.

Bob Dyachenko, owner of SecurityDiscovery.com, and Cybernews researchers discovered the data breach on an unsecured web instance.

The owner of the massive breach will likely never be discovered, but the researchers suggest it could be a malicious actor, data broker or service working with large amounts of data.

Initial investigations into the data indicate that it does not come from a new breach, but is actually a collection of previous breaches.

Of the 12 terabytes of records, the researchers also note that some are almost certainly duplicates.

However, the data breach is still extremely concerning due to the sensitive nature of the information released.

The researchers said: ‘The dataset is extremely dangerous because threat actors can use the collected data for a wide range of attacks.’

They say these attacks can include identity theft, sophisticated phishing schemes, targeted cyber attacks and unauthorized access to personal and sensitive accounts.

Data has been leaked from hundreds of different sites, more than twenty of which have exposed hundreds of millions of data.

The biggest leak comes from Tencent’s QQ, a popular Chinese messaging app that contained 1.5 billion records.

Experts warn that the data, which has been leaked from sites such as Linkedin, could be extremely dangerous.  Criminals can use this type of sensitive personal information to create a huge wave of cybercrime, including phishing attacks, identity theft and targeted cyber attacks

Experts warn that the data, which has been leaked from sites such as Linkedin, could be extremely dangerous. Criminals can use this type of sensitive personal information to create a huge wave of cybercrime, including phishing attacks, identity theft and targeted cyber attacks

This was followed by Weibo, the Chinese social media platform, which had 504 million records.

Some of the other biggest leaks came from MySpace (360 million), Twitter (281 million), Linkedin (251 million), and AdultFriendFinder (220 million).

The leak also included data from several government organizations from the US, Brazil, Germany, the Philippines, Turkey and others.

To see if your data has been affected by historical data breaches, you can use Cybernews’ data breach check.

Simply enter your email address or phone number into the search bar and click ‘check now’ to see if that account information has been leaked.

Cybernews says it is currently working on updating the tool to ensure it can check for data leaked in this latest breach.

Alternatively, Cybernews also has one searchable list of sites affected by the breach.

To see if your data has been affected by historical data breaches, you can use Cybernews' data breach checker.  Simply enter your email address or phone number into the search bar and click 'check now' to see if that account information has been leaked

To see if your data has been affected by historical data breaches, you can use Cybernews’ data breach checker. Simply enter your email address or phone number into the search bar and click ‘check now’ to see if that account information has been leaked

If you’re particularly concerned about the impact of a site you’re using, you can search the site name to see if any data has been leaked.

According to the researchers, the biggest concern is that this data could form the basis for a huge wave of cybercrime.

“If users use the same passwords for their Netflix account as they do for their Gmail account, attackers can use this to access other, more sensitive accounts,” they say.

“Aside from that, users whose data is included in the super-heavy MOAB may fall victim to spearphishing attacks or receive a large number of spam emails.”

If you’re concerned that your personal information has been leaked in this breach, the most important thing you should do is update your passwords.

By making sure you don’t use the same passwords for multiple accounts, you reduce the risk of one account compromising all your data.

HOW TO CHECK IF YOUR EMAIL ADDRESS HAS BEEN COMPROMISED

Am I pwned?

Cybersecurity expert and Microsoft regional director Tory Hunt leads ‘Am I pwned’.

The website allows you to check if your email has been compromised as part of any of the data breaches that have occurred.

If your email address appears, you will need to change your password.

Pwned passwords

To check whether your password may have been exposed in a previous data breach, go to the site’s homepage and enter your email address.

The search tool compares this to the details of historical data breaches that have made this information publicly visible.

If your password does appear, you are likely at greater risk of being exposed to hacking attacks, fraud, and other cybercrime.

Mr Hunt built the site to help people check whether or not the password they want to use is on a list of known hacked passwords.

The site does not store your password alongside any personally identifiable information and each password is encrypted

Other safety tips

Hunt offers three easy-to-follow steps for better online security. First, he recommends using a password manager, such as 1Password, to create and store unique passwords for each service you use.

Then enable two-factor authentication. Finally, stay informed of any breaches