22269 HQ Mixed Domains Leak Exposed 22,021 Login Credentials.
In June 2026, HEROIC analysts found a stealer log named "22269 HQ Mixed Domains" uploaded to a Telegram channel by a user distributing malware harvested credentials across many websites. The verified file contained 22,021 records, each pairing a login URL, an email address, and a plaintext password.
22,021 Working Logins Across Dozens of Sites
This log mixes credentials from many different websites rather than focusing on one service, meaning the 22,021 records inside cover email providers, retailers, and other online accounts that happened to be saved on infected devices. The "HQ" label indicates the distributor has already verified these logins work.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Associated Login URLs
Why This Matters
Verified, ready-to-use credentials across mixed domains make this log valuable for large scale credential stuffing, putting anyone in the 22,021 records at risk of account takeover, identity theft, and financial fraud if they reused passwords across sites.
How Stealer Logs Work
Stealer logs are built from malware infections that copy saved browser passwords from a device and send them to an attacker, who then combines results from many victims into one file. Mixed domain logs like this one are common because most people save passwords for several different sites in the same browser.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including mixed domain stealer logs like this one. Run a free scan to see if your credentials were among the 22,021 exposed here.
Breach Breakdown
22,021 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds