---
title: "12TB of consumer data leaked: What does it mean for merchants?"
date: 2024-01-30T14:33:00+00:00
author: Nikoleta Dimitriou
canonical_url: "https://www.ravelin.com/blog/mother-of-all-leaks-ato-advice"
section: Blog
---
Blog /[Account takeover](/resources?search=&category%5B0%5D=134546#resourceContainer "Go to Account takeover"), [Fraud trends](/resources?search=&category%5B0%5D=201169#resourceContainer "Go to Fraud trends")

# 12TB of consumer data leaked: What does it mean for merchants?

A massive 26bn PII records from across the world have been discovered doing the rounds on the dark web. How does this affect online merchants and their customers?

30 January 2024

![12TB of consumer data leaked: What does it mean for merchants?](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_blogSmall/201551/264_Data_Leak_Blog_Socials_Blog_885x505__1.webp)

On 24 January, a database of "fullz" – a fraudster term for sets of personally identifiable information (PII) – 12TB in size was discovered by cyberthreat researcher Bob Diachenko.

 With it come new opportunities for cyber criminals to defraud companies and consumers, as well as an increased interest in data leaks and their consequences by the public.   
  
So, what exactly happened? And, importantly, what does it mean for online merchants? We've prepared a short piece to help break it all down, explain **how it affects the online fraud landscape**, and provide some practical advice courtesy of Ravelin CEO Martin Sweeney.

## What happened?

Dubbed "the mother of all breaches" by Cybernews website – only to be "corrected" to "(grand)mother of all breaches)" by [the man who unearthed it](https://www.linkedin.com/posts/vdyachenko_mother-of-all-breaches-a-historic-data-leak-activity-7155298570126921730-GZB3/) – it's estimated to be the the largest set of breached credentials ever discovered, at 26 billion records and 12TB of data.

The PII is linked to individuals from around the world, including users of Chinese social media platforms Tencent and Weibo, as well as MySpace, LinkedIn, Dropbox and X/Twitter, among several others. In fact, this is not a single data leak but an aggregate record of **more than 3,800 data leaks**. This type of database is also called a COMB – short for compilation of multiple breaches.

It seems that a fraudster has taken the time to compile the data of thousands of leaks in one file – which makes the stolen PII easier to handle, share and browse. In essence, because of how massive and well-organized it is, bad actors are going to leverage it more often and more efficiently for various schemes.

Even, in fact, to feed into AI. It's not just fraud fighters [that employ machine learning](https://www.ravelin.com/blog/how-do-we-build-a-machine-learning-model); fraudsters have been eagerly adopting generative models, ML, LLMs and other types of automation that **help scale their operations**. One of the various consequences of this is, for example, the mass creation of synthetic identities, which are a way to further defraud both consumers and businesses. It's a chain reaction of cybercrime.

If you're wondering whether a new aggregate file would actually make a difference, it already has. Reports of massive account takeover (ATO) attacks (or attempts) have gone as far as the mainstream press in the past two months, with internal data at Ravelin confirming the trend.

## No surprise – Ravelin noted an increase in ATO

In fact, [Ravelin's fraud investigation experts](https://www.ravelin.com/support) have observed an increase account takeover attempts since late November, across the majority of our client accounts.

These have included, for instance, a significant (if largely unsuccessful) credential stuffing attack that saw **almost 1 million failed logins on a single day** in January. Brute-force attacks like these usually take place when low-level cybercriminals attempt to find credentials that have been reused across apps, platforms and services by the same individual, some of which might be more profitable to get into than others.

Another widely observed phenomenon was a **rise in logins to very old, inactive accounts** on our clients' websites. These were fraudsters using the leaked credentials to sign in and take advantage of the account however they can.

Ravelin's CEO, Martin Sweeney, weighs in:  
  
*"This news should not come as a surprise, unfortunately. The dataset that was discovered is an aggregate. It doesn’t come from a single source, which is one indication of **how easy it is** for cyber criminals to obtain this type of information.*  
  
*At Ravelin, we had already observed a steep rise in attempted account takeovers against our partners since late November, which was on par with new PII leaks. But we didn’t anticipate such a huge number – 26 billion records!"*

## Consequences? A chain reaction of fraud

In terms of consequences, the first and most immediate is an increase in account takeover attempts, as well as social engineering (that often leads to ATO itself).

It's important to note that this type of attack is a means to an end. No fraudster would ever stop at taking over a customer's account. They would use the data found within, or the access to the account itself, to enable further [ecommerce fraud](https://www.ravelin.com/blog/5-types-of-fraud-ecommerce-retailers), such as triangulation fraud or payment fraud.

In addition, this PII allows for phishing and spear-phishing attacks, identity theft and other cybercrime.

Ravelin's ATO Product Manager, Clayton Black, comments on the developments:

*"The scale of this data breach **makes every online merchant a target for account takeover**. Companies that never had a problem with ATO may soon find themselves inundated with customer complaints, transaction disputes, chargebacks and faced with an irreparable damage to their brand and consumer trust.*  
  
*Companies need to act now to address gaps in account defence measures and educate customers around basic protective behaviors, such as not reusing password and looking out for phishing emails."*

## What should merchants do about it?

For practical advice to merchants, we once again turned to Martin Sweeney:

"*My advice to merchants is to be proactive:*

- *Review your ATO protection and consider deploying it both at login and checkout.*
- *Fraudsters will be attempting to reuse these credentials across various services – encourage them to use unique passwords or even change theirs if found in the 12TB dataset.*
- *Listen to your fraud managers – they know your fraud landscape and weak points best.*
- *Remember that ATO and social engineering are attacks that enable all other manner of fraud, so stay up to date with your fraud protection across the board.*
- *Use [graph networks](https://pages.ravelin.com/how-to-use-graph-networks)! Leverage visualizations between accounts across your customers. This can help your fraud analysts more easily spot hidden connections between users and block entire networks of fraudsters.*"

### Further reading  

- Read more about **[what fraudsters do after they take over an account](https://www.ravelin.com/blog/what-do-fraudsters-do-after-they-take-over-an-account).**
- Find out [**how to limit the impact of account takeover**](https://www.ravelin.com/blog/how-to-limit-the-impact-of-account-takeover) when it does happen.
- Discover Ravelin's **[account takeover fraud](https://www.ravelin.com/insights/account-takeover-fraud)** insights.

## Author

![Nikoleta Dimitriou](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_avatarSmall/196785/1669287463716_2023-12-07-164059_ybjd.webp)

Nikoleta DimitriouSenior Content Manager

With a marketing career focused on technology, Nikoleta has worked for the data science, e-learning, and fraud industries, among others. Since 2023…

[More from this author](https://www.ravelin.com/author/nikoleta-dimitriou)

## Related content

[Blog / Fraud trends

### Online Retail Fraud Trends 2026: New global report

Refund abuse just outranked traditional forms of first-party abuse in terms of its negative impact on retailers – while 78% say fraud has stifled their growth to some extent.

![1669287463716 2023 12 07 164059 ybjd](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/196785/1669287463716_2023-12-07-164059_ybjd.webp)Nikoleta Dimitriou,Senior Content Manager](https://www.ravelin.com/blog/online-retail-fraud-trends-2026)

[Blog / 3DS &amp; SCA

### What's the difference between 3D Secure 1, 2 and 2.3?

 Strong Customer Authentication is required in more and more countries around the world. Here’s a quick explanation of the key differences between the 3D Secure versions.

![Catherine Jones](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/76597/kit-photo.webp)Catherine Jones,Product Director

![James hogan](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/274718/james-hogan.webp)James Hogan,Senior Product Manager – Payments Engineering](https://www.ravelin.com/blog/whats-the-difference-between-3d-secure-1-and-2)

[Blog / Fraud analytics

### Burner account detection requires continuous behavioral monitoring and network analysis

Today we explore ecommerce burner accounts and why it's important for merchants to home in on and ban them before they do harm.

![Unnamed 3](https://storage.googleapis.com/ravelin-website-assets-production/assets/images/_33x33_crop_center-center_none_ns/265422/unnamed-3.webp)Nelda Biltauere,Senior Fraud and Payments Researcher](https://www.ravelin.com/blog/ecommerce-burner-account-fraud)
