Breach Intelligence Report 02 Oct 2025

The AltairSupport Dump: 20,678 Stolen Login Credentials Hit Telegram

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 20,678
Source Type Stealer log
Origin Telegram
Password Type plaintext

HEROIC analysts flagged a stealer log file uploaded to Telegram on August 19, 2025 under the name PRIVATE PACK AltairSupport, containing 20,678 records. The file held email addresses, plaintext passwords, and URLs pointing to web endpoints and API hosts. This was the second AltairSupport private pack detected within days, suggesting an ongoing or multistage compromise rather than a one-time incident. The "PRIVATE PACK" designation in Telegram circles signals that the data is fresh and exclusivly packaged for buyers willing to pay for first access, meaning this file likely began circulatig in private channels before being detected by analysts.

Why This Is Dangerous

A fresh stealer log with plaintext passwords is the most immediately dangerous type of credential exposure. Unlike hashed password dumps that require cracking, this file delivers working login combinations directly to anyone who downloads it. With 20,678 records and no encryption standing between the attacker and the credentials, account takeover attempts can begin within minutes of someone obtaining the file. The presence of API host URLs adds another layer of risk, potentially exposing backend access to systems far beyond the original AltairSupport platform.

What Was Exposed

  • Email addresses
  • Plaintext passwords (no hashing, no encryption)
  • Web endpoint and service URLs
  • API host addresses
  • 20,678 total credential records

Why This Matters

The fact that two separate AltairSupport private packs appeared within days of each other is significant. It may indicate that the original infection produced a large dataset that was split and sold in batches, or that multiple systems were compromised in the same campaign. Either way, the combined exposure from both packs represents tens of thousands of affected accounts. For individuals and organizations using AltairSupport-connected services, this breach compounds the risk considerably. Each new pack refreshes the threat, since buyers who missed the first file now have another opportunity to obtain similar data.

How Stealer Logs Work

Stealer malware gets onto a device through a phishing email, a fake software download, or a malicious link. Once running, it silently sweeps through saved browser passwords, locally stored credentials, and application configuration files. It records URLs, API keys, and any other access tokens it encounters, then packages everything into a structured log file and sends it to the attacker. The attacker then monetizes the data by selling it in bulk or distributing it through Telegram channels to other criminals. The AltairSupport dump followed this exact path: infection, harvest, and public sale on Telegram within a matter of weeks.

Check If You Are Affected

If you used AltairSupport or any service with connected credentials, check your exposure now with HEROIC's free breach scanner. HEROIC monitors over 400 billion breached records, including private packs and stealer log files from Telegram channels that most breach databases never see. A free search takes seconds. If your email appears in this dump or any related breach, you will know immediately and can take action before someone uses those credentials against you.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 02 Oct 2025
Check in 5 seconds

20,678 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,693 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $149.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance