The 5d Stealer Log: 36,097 Passwords Harvested by Malware
In July 2026, HEROIC analysts identified a stealer log file named "5d" circulating on Telegram. The file contained 36,097 records, including email addresses, plaintext passwords, and the URLs those credentials were entered on, all harvested directly from infected devices. Why This Is Dangerous: This isn't a list of old, recycled leaks. A stealer log is pulled straight from malware running on someone's device, which means the passwords are current and paired with the exact site each one unlocks. With over 36,000 records, this single file gives attackers a large, ready-made set of live targets. What Was Exposed: The 5d stealer log contains email addresses, plaintext passwords, and URLs linked to each stolen credential. Why This Matters: Because each password in the log is matched to a specific URL, attackers don't need to guess where a credential works. They can log straight into email, banking, or shopping accounts, and if any of these passwords were reused elsewhere, the damage spreads through credential stuffing into accounts far beyond the original infection. How a Stealer Log Like This Is Created: Infostealer malware infects a device, often through a pirated download, phishing email, or malicious ad, then quietly harvests saved browser passwords, autofill data, and cookies. Everything gets bundled into a log file and sent back to the attacker, who then sells, trades, or uploads it, as happened here. Check If You Are Affected: If your device may have been infected or you're unsure whether your credentials are part of the 5d log, HEROIC's free breach scanner checks your email against more than 400 billion leaked records, so you can find out and take action immediately.
Breach Breakdown
36,097 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds