1,511,612 Plaintext Passwords Were Just Dumped on Telegram
HEROIC identified an exceptionally large stealer log collection labeled "1.5M Mix" that was uploaded to Telegram in April 2025. The dump contains 1,511,612 records, making it one of the most substantial single credential files in circulation. Every entry includes an email address, a plaintext password, and the URL of the service where the credential was stolen, providing attackers with an industrial-scale database for automated exploitation.
Over 1.5 Million Passwords in Unprotected Plaintext
The scale of this leak is extraordinary. All 1,511,612 passwords are stored in plaintext, meaning they require absolutely no technical effort to use. At this volume, even if only a small percentage of credentials remain active, tens of thousands of accounts are immediately accessible to anyone who downloads this file. The absence of any encryption makes every single entry a live vulnerability waiting to be exploited.
What Was Exposed
- Email Addresses — over 1.5 million unique accounts across numerous providers
- Plaintext Passwords — every password stored in completely readable, unencrypted form
- URLs — documenting which services and websites each credential was captured from
Credential Stuffing at Unprecedented Scale
A dump of over 1.5 million credentials is a goldmine for credential stuffing botnets. These automated systems can test every combination against hundreds of popular services simultaneously. With password reuse rates estimated between 50 and 80 percent among average users, a dump this size could yield hundreds of thousands of successful account takeovers across banking, email, social media, streaming, and enterprise platforms.
The Massive Infrastructure Behind This Collection
Compiling over 1.5 million credentials requires a widespread infostealer operation involving thousands of infected devices. The malware responsible harvests browser-stored passwords, captures live form submissions, and steals authentication cookies and tokens. The individual log files from each infected device are then aggregated by malware operators into massive compilations like this one. The result is a dataset that represents the combined digital footprint of thousands of victims, distributed freely on Telegram for anyone to exploit.
Check If Your Credentials Were Exposed
With over 1.5 million credentials in this single dump, the statistical probability of inclusion is significant for active internet users. HEROIC's breach scanner indexes more than 400 billion compromised records and is the most comprehensive tool available for checking your exposure. Search your email and passwords now to determine if you are in this dump or any other known breach, and take immediate action to change all compromised credentials.
Breach Breakdown
1,511,612 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds