122 Plaintext Passwords From the 272570_BR Telegram Stealer Log Just Surfaced
HEROIC analysts identified a stealer log file uploaded to Telegram in June 2023, tracked as 272570_BR_177.192.120.216_08-06-23. The file exposed 122 records containing plaintext passwords, email addresses, and URLs pulled directly from compromised endpoints in the United States. The data was shared openly by an anonymous Telegram user, making it freely accessible to anyone looking to exploit it.
Why the 272570_BR Stealer Log Is Dangerous
This log contains plaintext passwords, meaning the credentials are readable without any cracking. Attackers can take an email address paired with its plaintext password and immediately attempt to log into email accounts, banking apps, social media, and any other service where that password was reused. No technical skill is required. The URLs in the log also reveal exactly which services the victim was logged into at the time of infection.
What Was Exposed in the 272570_BR Stealer Log
- Email Addresses
- Plaintext Passwords
- URLs (websites and services accessed by victims)
Why This Matters
When attackers get plaintext passwords, credential stuffing attacks become trivially easy. They load the email-password pairs into automated tools and test them across hundreds of websites at once. Victims who reuse passwords across multiple accounts are especially at risk of account takeover, unauthorized purchases, and identity theft. Even a small 122-record file like this can cause real financial and personal harm.
How Stealer Logs Like 272570_BR Work
A stealer log is created by malware that silently infects a computer or phone. Once installed, the malware harvests everything stored or typed in the browser: saved passwords, active session cookies, email credentials, and the URLs of sites visited. That data gets packaged into a file and sent back to the attacker. These log files are then sold or shared on Telegram channels and dark web forums, where anyone can download and exploit them.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you whether your email or password has appeared in this or any other known breach. If your credentials were in this Telegram stealer log, you need to change your passwords immediately and enable two-factor authentication on every account. Run a free search at HEROIC to find out right now.
Breach Breakdown
122 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds