The AltairSupport Dump: 20,678 Stolen Login Credentials Hit Telegram
HEROIC analysts flagged a stealer log file uploaded to Telegram on August 19, 2025 under the name PRIVATE PACK AltairSupport, containing 20,678 records. The file held email addresses, plaintext passwords, and URLs pointing to web endpoints and API hosts. This was the second AltairSupport private pack detected within days, suggesting an ongoing or multistage compromise rather than a one-time incident. The "PRIVATE PACK" designation in Telegram circles signals that the data is fresh and exclusivly packaged for buyers willing to pay for first access, meaning this file likely began circulatig in private channels before being detected by analysts.
Why This Is Dangerous
A fresh stealer log with plaintext passwords is the most immediately dangerous type of credential exposure. Unlike hashed password dumps that require cracking, this file delivers working login combinations directly to anyone who downloads it. With 20,678 records and no encryption standing between the attacker and the credentials, account takeover attempts can begin within minutes of someone obtaining the file. The presence of API host URLs adds another layer of risk, potentially exposing backend access to systems far beyond the original AltairSupport platform.
What Was Exposed
- Email addresses
- Plaintext passwords (no hashing, no encryption)
- Web endpoint and service URLs
- API host addresses
- 20,678 total credential records
Why This Matters
The fact that two separate AltairSupport private packs appeared within days of each other is significant. It may indicate that the original infection produced a large dataset that was split and sold in batches, or that multiple systems were compromised in the same campaign. Either way, the combined exposure from both packs represents tens of thousands of affected accounts. For individuals and organizations using AltairSupport-connected services, this breach compounds the risk considerably. Each new pack refreshes the threat, since buyers who missed the first file now have another opportunity to obtain similar data.
How Stealer Logs Work
Stealer malware gets onto a device through a phishing email, a fake software download, or a malicious link. Once running, it silently sweeps through saved browser passwords, locally stored credentials, and application configuration files. It records URLs, API keys, and any other access tokens it encounters, then packages everything into a structured log file and sends it to the attacker. The attacker then monetizes the data by selling it in bulk or distributing it through Telegram channels to other criminals. The AltairSupport dump followed this exact path: infection, harvest, and public sale on Telegram within a matter of weeks.
Check If You Are Affected
If you used AltairSupport or any service with connected credentials, check your exposure now with HEROIC's free breach scanner. HEROIC monitors over 400 billion breached records, including private packs and stealer log files from Telegram channels that most breach databases never see. A free search takes seconds. If your email appears in this dump or any related breach, you will know immediately and can take action before someone uses those credentials against you.
Breach Breakdown
20,678 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds