198,318 Shopping Site Passwords Dumped on Telegram
In January 2023, HEROIC's DarkHive threat intelligence platform identified a large-scale stealer log labeled "198K Shopping Sites" that was uploaded to Telegram. The dataset is substantial, containing 198,318 records of stolen credentials specifically targeting online shopping platforms. Each record includes an email address, a plaintext password, and the URL of the e-commerce site where the login was intercepted.
Why Plaintext Shopping Passwords Are High-Value Targets
Shopping site credentials are among the most lucrative for cybercriminals because accounts often have saved payment methods, stored addresses, and purchase histories. With every password in this dump stored in plaintext, attackers face zero technical hurdles to accessing these accounts. They can place fraudulent orders, steal stored payment details, redirect shipments, and drain gift card balances — all without needing to crack a single hash.
What Was Exposed
- Email Addresses — linked to shopping accounts that may store payment information
- Plaintext Passwords — immediately usable for unauthorized purchases and account takeover
- URLs — identifying the specific e-commerce platforms where each credential was stolen
From Shopping Accounts to Full Identity Theft
Credential stuffing attacks using shopping site logins are especially dangerous. Attackers test these passwords against email providers, banking sites, and payment platforms. A compromised shopping account reveals personal details — home address, phone number, payment methods — that fuel broader identity theft. With nearly 200,000 entries in this single dump, the potential for widespread financial damage is significant.
How Infostealers Target Online Shoppers
The credentials in this dataset were harvested by infostealer malware running on victims' devices. Infostealers commonly infect computers through fake deals, counterfeit coupon extensions, and trojanized shopping apps. Once installed, they silently capture every login credential saved in the browser — including passwords for Amazon, eBay, Walmart, and hundreds of other retailers. The stolen data is compiled into log files and distributed to other criminals through Telegram channels.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence platform has cataloged over 400 billion compromised records from breaches and stealer log leaks worldwide. Use HEROIC's free breach scanner to check whether your email address or password appears in the 198K Shopping Sites dump or any other indexed breach. Protecting your shopping accounts starts with knowing whether your credentials have been compromised.
Breach Breakdown
198,318 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds