1 600 000 CORP Stealer Log Leak Exposes 1.38M Passwords
In August 2025, a threat actor uploaded a stealer log file labeled "1 600 000 CORP" to a Telegram channel used for trading stolen data. The file contained 1,381,891 records pulled from malware-infected devices, including email addresses, plaintext passwords, and the URLs those credentials were used on.
A Name That Overstates the Real Number
The label "1 600 000 CORP" suggests a much larger haul than what was actually confirmed. The verified count from this specific file is 1,381,891 records, still a substantial exposure, but it's worth noting that stealer log names are chosen by the people distributing them and don't always match the real data inside.
Why This Is Dangerous
Stealer logs like this one are collected by infostealer malware that quietly runs on a victim's computer, scraping saved browser passwords, autofill data, and session information. Because the passwords in this file were stored in plaintext, anyone who downloads the log can read them instantly, with no cracking or decryption required.
What Was Exposed
- Email addresses tied to the infected accounts
- Plaintext passwords, readable without any additional effort
- URLs showing which sites and services each login belonged to
Why This Matters For You
When a password is exposed in plaintext alongside the email address and site it belongs to, criminals have everything they need to walk straight into an account. This kind of data fuels credential stuffing attacks, where automated tools test the same email and password combination across banking, shopping, and social media sites. It also opens the door to account takeover, identity theft, and financial fraud, especially if the exposed password is reused anywhere else.
How a Stealer Log Like This Gets Made
Infostealer malware typically arrives through a fake software download, a cracked game, or a malicious email attachment. Once installed, it silently harvests everything saved in the browser: usernames, passwords, cookies, and autofill records. That stolen data is bundled into a log file and sold or shared in Telegram channels like the one this file came from, often within days of the infection.
Check If Your Information Was Exposed
With 1,381,891 records involved, there's a real chance your email address is one of them. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including stealer logs like this one, so you can find out in seconds whether your credentials were exposed and take action before someone else uses them.
Breach Breakdown
1,381,891 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds