110k PayPal Target Log Leaked 107,832 Emails and Passwords
In January 2023, HEROIC analysts identified a stealer log file titled "110k paypal target," uploaded to a Telegram channel. The file contained 107,832 records made up of email addresses, plaintext passwords, and the URLs of the login pages the credentials were tied to, with a naming convention suggesting the data was gathered with PayPal logins specifically in mind.
Why This PayPal-Targeted Log Is Dangerous
Stealer logs built around a specific target like PayPal are especially concerning because the credentials inside are curated rather than random, meaning the people compiling the file believed these logins had financial value. With passwords exposed in plaintext, an attacker does not need to break any encryption, they can simply try each email and password combination against PayPal or any other site where the same password may have been reused.
What Was Exposed in the 110k PayPal Target Log
- Email addresses
- Plaintext passwords paired with each account
- URLs indicating the login pages tied to the credentials
Why This Matters
When a stealer log is labeled around a financial service, the risk of direct financial fraud increases. Attackers can attempt to log into payment accounts, transfer funds, or make purchases before a victim notices anything unusual. Beyond the immediate financial risk, any of these 107,832 email and password pairs could also be reused successfully on email, shopping, or banking accounts elsewhere, opening the door to credential stuffing and identity theft.
How Stealer Logs Work
This type of leak comes from info-stealing malware installed on a victim's computer, often through a fake tool, cracked software, or phishing download. The malware searches the browser for saved logins, autofill entries, and cookies, then exports everything into a file. Criminals frequently label these files by the type of account they contain, in this case PayPal, to make it easier for buyers to find the accounts most valuable to them once the file is sold or shared, as this one was on Telegram.
Check If You Are Affected
If you have a PayPal account or reuse passwords across financial services, checking your exposure is a good idea. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one, to show you instantly if your email has been compromised.
Breach Breakdown
107,832 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds