The alice.it Data Leak: Exactly 2,779 Passwords Exposed
In June 2026, HEROIC analysts found a stealer log labeled "alice.it" being shared on Telegram. The file contained exactly 2,779 records, each pairing an email address with a plaintext password and the login URL it was captured from.
Why This Is Dangerous
Every one of these 2,779 records already includes a working email, an unencrypted password, and the exact site it unlocks. There's no cracking or guessing involved, so anyone who gets this file can log in immediately.
What Was Exposed
- Email addresses tied to alice.it and related accounts
- Plaintext passwords stored without encryption
- Login URLs showing exactly which sites each password unlocks
Why This Matters
If any of these 2,779 passwords were reused elsewhere, attackers can use them for credential stuffing, potentially leading to account takeover on banking, shopping, or social media accounts far removed from the original leak.
How This Stealer Log Was Collected
Stealer malware infects a device, quietly copies the passwords saved in the browser along with the matching login URL, and sends everything back to whoever controls the malware. The "alice.it" file appears to be a batch pulled from that kind of harvest and shared on Telegram.
Check If You Are Affected
With 2,779 records in this one file, there's a real chance your information is part of it. HEROIC's free breach scanner searches more than 400 billion leaked records, so you can check your email in seconds and change any exposed passwords right away.
Breach Breakdown
2,779 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds