Vodafone is associated with a leaksear.ch indexed count of 1,000 records from a May 11, 2026 Lapsus$ source-code dump, with the indexed subset described as coming from an exposed all_users_passwords.csv file containing user identifiers, usernames or email-style logins, and plaintext passwords (leaksear.ch metadata). Public reporting describes a broader approximately 7.1GB source-code archive, but that public scale is not the leaksear.ch indexed count and should not be read as 7.1GB of indexed credentials Cybernews.
What happened
leaksear.ch metadata records the breach date as May 11, 2026, the indexing date as June 30, 2026, and no reporter (leaksear.ch metadata). The updated metadata identifies this dataset with the 2026 Lapsus$ Vodafone source-code dump rather than the older Vodafone Iceland context discussed in the prior version (leaksear.ch metadata).
Cybernews reported that Lapsus$ claimed responsibility and published approximately 7.1GB of Vodafone internal source code after an alleged refusal to negotiate, and its researchers described source code and repository structure for projects including Vodafone OnePortal and Cyberhub Cybernews. Vodafone's 2026 Annual Report states that in March 2026 a compromised third-party software developer package was used to gain unauthorized access to some Vodafone Business code repositories Vodafone Annual Report 2026, page 55.
Vodafone also stated that the impact was limited to source code, was contained and investigated, and that it did not identify any impact to customer personal data or production systems Vodafone Annual Report 2026, page 56. Those statements cover the broader code-repository incident, while the leaksear.ch metadata separately identifies a 1,000-record credential-style subset and does not classify the accounts as customer, employee, developer or test accounts (leaksear.ch metadata).
What data was exposed
For this Vodafone dataset, the leaksear.ch indexed count is 1,000 records (leaksear.ch metadata). Searchable fields on leaksear.ch are email, username and password (leaksear.ch metadata).
The stored field that is not described as searchable is source_user_id (leaksear.ch metadata). The metadata description says the records include user identifiers, usernames or email-style logins, and plaintext passwords from an exposed all_users_passwords.csv file in the Lapsus$ dump (leaksear.ch metadata).
The leaksear.ch field inventory does not list names, phone numbers, postal addresses, payment data, SMS messages, national identifiers, source files or hardcoded database credentials for this 1,000-record index (leaksear.ch metadata). Cybernews discussed source code and hardcoded PostgreSQL credentials in the larger archive, but those public details are separate from the searchable and stored fields in the leaksear.ch index Cybernews.
Why this matters
Email or username plus plaintext password pairs are high-value credential material, especially where a person reused a password outside Vodafone. NIST guidance says a memorized secret should be changed when there is evidence it has been compromised, and CISA says MFA makes account takeover harder NIST CISA.
For security researchers and incident responders, the priority is to match exposed emails and usernames against authorized identity stores, reset any confirmed matching or reused passwords, revoke active sessions where feasible, and review repository and supplier access paths connected to the March 2026 code-repository incident. Because Vodafone publicly reported no identified impact to customer personal data or production systems, teams should not treat this 1,000-record index as proof of a broader customer database breach unless they have additional evidence Vodafone Annual Report 2026, page 56.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include email, password, and username.