1,098 Plaintext Passwords Were Just Dumped in the Uruguay 4 Leak
HEROIC discovered a stealer log file labeled "Uruguay 4" on Telegram, originally uploaded in January 2023. This is the fourth installment from a threat actor systematically targeting Uruguayan users, and it contains 1,098 stolen credential records. Each record includes an email address, a plaintext password, and the URL of the service where the login was captured. The ongoing numbering suggests a persistent operation with multiple previous batches already in circulation.
Plaintext Credentials Require No Effort to Exploit
Every password in the Uruguay 4 file is stored as unencrypted, readable text. Attackers do not need to run any decryption tools or brute-force algorithms. They can copy a password directly from the file and paste it into a login page. For the 1,098 people whose credentials are in this dump, the barrier to account compromise is nonexistent — anyone with the file has everything needed to log in.
What Was Exposed
- Email Addresses — Uruguayan user accounts from various email providers and online services
- Plaintext Passwords — stored in readable form with no cryptographic protection whatsoever
- URLs — the specific Uruguayan and international websites where each credential was stolen
Credential Stuffing Crosses Borders
While the Uruguay 4 file targets Uruguayan users specifically, the credential-stuffing attacks it enables are not limited by geography. Attackers test each email-password pair against global platforms — Gmail, Facebook, Instagram, Netflix, Amazon, and banking services that operate internationally. A Uruguayan user who reuses their password across local and global services gives attackers the keys to their entire digital presence with just one compromised credential from this dump.
The Stealer Log Operation Targeting Uruguay
The "4" in the filename indicates this is at least the fourth batch from the same source, pointing to an organized and sustained credential theft operation. The data originates from infostealer malware — trojans like Vidar, RedLine, or Lumma that infect devices through malicious downloads, phishing messages, or compromised websites popular in the Uruguayan market. The malware silently captures browser-saved passwords, cookies, and autofill data, then exfiltrates everything to the attacker. The operator filters the stolen data by country and releases it in numbered batches on Telegram.
Check If Your Credentials Were Exposed
If you are a Uruguayan internet user or have accounts on Uruguayan services, the Uruguay 4 leak may contain your credentials. HEROIC's data breach scanner searches more than 400 billion compromised records to find out if your email or password has been exposed in this or any other known breach. Identifying your exposure early is the most effective way to change passwords and enable additional security before attackers act.
Breach Breakdown
1,098 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds