Brazilian Users Hit: Telegram Log Leaks 307,412 Passwords
On June 17, 2026, a Telegram user uploaded a stealer log file labeled "BRAZIL" to a public channel, exposing 307,412 records of stolen login data. The file contains email addresses, plaintext passwords, and the URLs of the login pages those credentials belong to, all harvested from malware-infected devices rather than taken from any single company's servers.
Who This Leak Targets
The "BRAZIL" label points to a stealer log that was specifically sorted and packaged around Brazilian users and the accounts they log into. Threat actors often organize stealer logs this way, by country, because it lets buyers on Telegram and dark web forums quickly find credentials tied to a particular region's banks, retailers, and services. With more than 307,000 records in this batch, the scale here is large enough to affect a significant number of Brazilian internet users and anyone who logged into Brazil-based services from an infected device.
What Was Exposed in This Leak
- Email addresses
- Plaintext passwords
- URLs of the associated login pages
Why This Matters for You
Because the passwords in this file are stored in plaintext, no cracking is needed before an attacker can try them. With 307,412 working email-and-password pairs to work through, criminals typically automate the process, running credential stuffing attacks across banking, email, and shopping sites to find accounts where the same password still works. If you reuse passwords across multiple sites, a single exposed login here can lead to account takeover, financial fraud, or identity theft.
How This Stealer Log Was Built
Stealer logs come from malware that quietly infects a device, often through a pirated download, a fake software crack, or a malicious attachment, and then copies whatever the browser has saved: stored passwords, autofill data, and the web addresses tied to each one. Once collected, the stolen data is sent back to the attacker, who sorts it by region or platform and packages it into files like this "BRAZIL" dump before sharing or selling it through channels like Telegram.
Check If You Are Affected
Don't leave it to chance. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including stealer log dumps like this one, and tells you instantly if you've been exposed. Run a free scan now and find out where you stand.
Breach Breakdown
307,412 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds