233 Facebook-Linked Passwords Exposed in a Telegram Stealer Log
233 records. That is how many accounts turned up in a Telegram-uploaded stealer log labeled ADVERTISE-NOREPLYSUPPORT.FACEBOOK.COM, posted in April 2025. Each record contains an email address, a plaintext password, and the URL each credential was captured from. The file references Facebook's advertising support domain, but this is a stealer-log credential harvest from infected devices, not a breach of Facebook's own systems.
Why This Facebook-Linked Leak Is Dangerous
Credentials tied to advertising and support domains are especially valuable to criminals because they often unlock access to business ad accounts, not just personal profiles. With 233 plaintext passwords exposed here, anyone whose login touched this domain is at risk of having their account, and any linked ad spend or business page, taken over directly.
What Was Exposed in This Stealer Log
- Email Addresses - the account identifiers behind each captured login
- Plaintext Passwords - exposed in fully readable form with no encryption
- URLs - the exact advertising and support pages each credential was used on
Why This Matters if You Are in This 233-Record File
A plaintext password linked to a business or advertising login is a direct path to account takeover, and from there to financial fraud if ad billing details are attached. Because people frequently reuse passwords across personal and work accounts, criminals also use files like this one for credential stuffing against email, banking, and shopping sites, which can quickly escalate into identity theft.
How This Facebook-Linked Stealer Log Was Created
Stealer malware on an infected device silently copies every password saved in the browser, including logins used for Facebook's advertising and support tools. That harvested data, 233 credential pairs in this case, was bundled into a log file and shared on Telegram, where it can be bought, sold, or used directly by whoever downloads it.
Check If You Are Affected
If you manage a Facebook ad account or business page, this is worth checking today. HEROIC's free breach scanner searches more than 400 billion exposed records, including stealer logs like this one, so you can confirm your exposure and lock down any account still using a leaked password.
Breach Breakdown
233 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds