420,039 Passwords From 420K USA Corp Mix Found on the Dark Web
HEROIC analysts identified this stealer log on June 30, 2026. The breach exposed 420,039 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as the 420K USA Corp Mix stealer log.
Why This Is Dangerous
With over 420,000 records and a corporate mix designation, this log contains credentials from US business accounts alongside personal ones. Corporate credentials are especially valuable to attackers, enabling business email compromise, corporate espionage, and access to internal systems and customer data.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of associated US corporate and personal login pages
Why This Matters
At 420,039 records, this log is large enough to fuel broad credential stuffing campaigns across banking, email, and enterprise platforms. Corporate account access can enable attackers to pivot deeper into business networks, access sensitive data, and commit financial fraud targeting both companies and their employees.
How This Stealer Log Works
Infostealer malware spreads onto corporate and personal devices through malicious downloads, phishing attachments, or fake software updates, then silently collects every saved password and login URL from the browser. Data from many infected machines is aggregated into large batches like this 420,000-record corporate mix and traded on Telegram and dark web forums.
Check If You Are Affected
HEROIC's free breach scanner searches 400 billion records including stealer logs like this one. Search your email now. Free, takes seconds.
Breach Breakdown
420,039 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds