74,744 Stolen Passwords From Mansory 6 Found on the Dark Web
HEROIC analysts identified this stealer log on 26-Dec-2025. The breach exposed 74,744 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as Mansory 6 uploaded by a Telegram User.
Why This Is Dangerous
This breach contains 74,744 plaintext passwords tied directly to email addresses and the websites they were used on. Because the passwords are in plain text, there is no additional decryption step needed before an attacker can try to use them. The URLs included in this dataset reveal which services were targeted, giving criminals a roadmap for where to attempt unauthorized logins.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
Exposed plaintext credentials are used in credential stuffing attacks, where automated tools try stolen username and password combinations across many platforms simultaneously. Anyone who uses the same password on multiple sites is at elevated risk. This type of breach contributes directly to account takeovers, identity theft, and financial fraud.
How Stealer Logs Work
Stealer logs are files generated by malware installed on a victim's device without their knowledge. The malware captures login credentials as they are entered, harvests passwords saved in browsers, and records the URLs of sites visited. These logs are collected and shared or sold through private Telegram channels and dark web forums.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records from known breaches. Search your email address now to find out if your credentials appear in this breach or others. The scan is free and takes seconds.
Breach Breakdown
74,744 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds