914 Stolen Logins in the 1000 .CA Mail Access Leak Could Unlock More
HEROIC analysts uncovered a stealer log named "1000 .CA Mail Access," uploaded to a Telegram channel and dated to February 14, 2026. Despite the round number in its file name, the log contains 914 verified records of email access credentials, each pairing an email address with a plaintext password and the login URL for the account. The ".CA" tag points to Canadian webmail accounts, giving whoever holds this file direct, working access to hundreds of real inboxes.
Why This Is Dangerous
An email inbox is rarely the final target, it is the door that opens every other door. Once an attacker logs into one of these 914 accounts, they can request password resets for banking apps, shopping accounts, and social media profiles, then intercept the reset links or verification codes that land right in that same inbox. A single stolen mail login can chain into a full takeover of someone's financial and personal life in a matter of minutes.
What Was Exposed
- 914 email addresses tied to active Canadian mail accounts
- Plaintext passwords stored with no encryption
- Login URLs identifying the exact webmail service for each account
Why This Matters
Because email is the recovery method for nearly every other online account, this leak carries risk far beyond the inbox itself. An attacker who gets in can reset banking credentials, hijack social media profiles, and lock the real owner out entirely. If any of these 914 people reused their mail password on another site, credential stuffing attacks make the damage spread even faster, turning one compromised account into many and opening the door to identity theft and financial fraud.
How Mail Access Logs Like This Get Built
This file was generated by infostealer malware, which infects a device through sources like pirated software, fake installers, or malicious attachments, then quietly copies saved browser passwords and login pages. The malware bundles everything into a log and sends it to whoever controls the infection, who filters it down to a working set of email accounts before selling or sharing it on Telegram, exactly where HEROIC found this one circulating.
Check If You Are Affected
If you use a .CA webmail address or have reused your email password anywhere else, it is worth checking now. HEROIC's free breach scanner compares your email against more than 400 billion leaked records, including stealer logs and mail access dumps like this one, so you can see your exposure and lock down your accounts before someone else gets there first.
Breach Breakdown
914 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds