In June 2025, what has been dubbed “the largest data leak in history” revealed over 16 billion login credentials were discovered in a “mega dump” on the dark web. Compiled from over 30 data sources including older breaches, previously stolen usernames and passwords, and information harvested by infostealers via malware software, hackers were able to successfully infiltrate multiple systems. As so many people re-use passwords across different platforms, attackers can use this information and input the same credentials (often through bots) to attempt logins on banking apps, corporate systems, email accounts, social media, and more. This is what’s known as Credential Stuffing.
{You can check out this Time Article for more information here.}
Credential stuffing is a serious type of cyberattack that is increasing in frequency as malicious actors become more sophisticated in their approach. Because they’re not guessing passwords, rather using known login details, it is a far more efficient data hacking technique.
A Wake-Up Call for Cybersecurity Worldwide
Major platforms including Google, Microsoft, Facebook, Apple, and Telegram were named as some of the domains in the breached dataset, and the worst thing? None of these companies were directly hacked thanks to credential stuffing.
While many of the exposed credentials came from known data breaches over the last decade, a significant proportion appeared to be newly harvested through malware that infected individual devices. Not only did they steal usernames and passwords, but session tokens, browser cookies, and authentication data as well. With this amount of data, cybercriminals can then bypass extra security measures including two-factor authentication (2FA), and impersonate users to hijack their accounts without even needing to know the password.
For local Australian businesses, the implications could mean your customer or employee credentials may now be exposed – potentially allowing hackers to access your systems.
Notifiable Data Breaches and Business Obligations
We’ve shared some blog articles in the past on Notifiable Data Breaches which you can check out here and here.
Under the Privacy Act 1988, as amended by the Notifiable Data Breaches (NDB) scheme, Australian organisations are legally required to notify affected individuals and the Office of the Australian Information Commissioner (OAIC) when a data breach is likely to result in serious harm. This includes not only actual breaches of your own systems, but also situations where user data is exposed due to poor credential hygiene or indirect access – such as through third-party services or reused passwords.
A breach that enables credential stuffing attacks may trigger the notification obligation if it results in unauthorised access to personal information. For example, if staff credentials reused from a breached platform are used to access sensitive company databases, and those records include customer data, the business must assess and potentially report the breach under the NDB scheme.
Additionally, under the Australian Cyber Security Strategy, businesses are increasingly expected to adopt stronger cyber hygiene practices including:
- Enforcing multi-factor authentication
- Monitoring for compromised credentials
- Training staff on phishing and password best practices
- Deploying Zero Trust architecture and real-time monitoring tools
What Should Businesses Do Now?
A proactive approach would be to assume that at least some of your users or employees have been affected by the “world’s largest data breach.” The safest course of action is to:
- Encourage immediate password resets across internal systems (and to do this often)
- Audit user access logs for suspicious behaviour, adapt response plans
- Revoke active sessions and tokens
- Promote password managers and non-reusable credentials
- Consider transitioning to passkey-based authentication, which removes the need for passwords altogether
Even businesses that are not bound by the Privacy Act (e.g. some small businesses) are still subject to the reputational damage and operational risk that credential stuffing can cause. Legal liability may also arise in contract, negligence or under consumer protection law if customers are affected due to inadequate security controls.
The Legal Implications of Credential Stuffing
As with most intersections of technology and the law, the sophistication of credential stuffing makes it hard to keep up. Working within our current legal frameworks, credential stuffing can pose significant compliance and governance risks but with vigorous monitoring it can help minimise the impact. Ensure all of your business systems are secure and regularly updated with robust cybersecurity measures, employee training is regular and up-to-date, and response plans are adaptive and responsive to current evolving risks. It’s imperative you are also aware of current Privacy Law reforms and how this may impact your business.
If your business is unsure whether it’s meeting its legal obligations around data protection or unaware of current Privacy Laws and how this impacts your commercial enterprise, our team can help. Get in touch with us here.