140K France Domains MIX Leak Exposes 116,222 Emails and Passwords
HEROIC Analysts Uncover the "140K France Domains MIX" Stealer Log
In April 2023, HEROIC's threat intelligence team identified a stealer log circulating on Telegram under the label "140K France Domains MIX." The file contained 116,222 records, and each one paired a victim's email address with a plaintext password and the exact URL of the login page that credential unlocked. The dataset is now cataloged in HEROIC's breach intelligence database so anyone affected can check their exposure.
Why Plaintext Passwords Tied to URLs Make This Log So Dangerous
Most leaked credential sets only include a username and a scrambled password that still has to be cracked before it's useful. This one is different. Every password in the 140K France Domains MIX log is stored in plain text, and it's already matched to the specific site it belongs to. A criminal doesn't need to guess or crack anything: they can copy an email, password, and URL straight into a browser and be logged in immediately. That is exactly the kind of data automated credential-stuffing tools are built to consume at scale.
What Was Exposed in the 140K France Domains MIX Log
- Email addresses tied to each victim
- Plaintext passwords, stored without any encryption or hashing
- URLs identifying the exact login page each credential pair unlocks
Why This Matters If You've Ever Reused a Password
Because these credentials are matched directly to working login pages, the most immediate risk is account takeover: an attacker logs in as the victim on the exact site the password belongs to. The bigger danger is password reuse. If any of the 116,222 people in this file used the same email and password combination elsewhere, including on email, banking, or shopping accounts, that reuse turns a single stolen password into access across multiple accounts. This is the same technique behind most large-scale credential-stuffing attacks, and it is often the first step toward broader identity theft.
How a "Domains Mix" Stealer Log Like This Gets Built
Stealer logs come from information-stealing malware that infects a device, often through cracked software, fake downloads, or phishing links. Once installed, the malware quietly reads passwords saved in the victim's browser and sends them, along with the associated URLs, back to the attacker. Logs collected from many infected computers are then sorted and bundled by the uploader, in this case grouped as a "mix" of France-linked domains, before being shared or sold in Telegram groups. The "MIX" in the name simply means the file combines credentials from many different victims and websites rather than coming from a single company's breach.
Check If Your Email Was in the 140K France Domains MIX Leak
The only way to know if your credentials were part of this leak is to check. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including stealer logs like this one, to tell you instantly if your email address has been exposed. If you find a match, change that password immediately, avoid reusing it anywhere else, and turn on two-factor authentication wherever it's available.
Breach Breakdown
116,222 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds