Researchers Link Canada Corp Mail Leak to 1,075 Stolen Logins
HEROIC analysts have linked a stealer log labeled "CANADA CORP-OTHERS-PRO MAILS TEST SAMPLE," uploaded to Telegram in February 2026, to 1,075 exposed records. Each entry pairs an email address with a plaintext password and the login URL it was captured from.
Why This Is Dangerous
Analysts note that every one of these 1,075 records already contains a ready-to-use email, password, and login URL, meaning attackers don't need to crack or guess anything before accessing the accounts involved.
What Was Exposed
- Email addresses tied to the affected Canada Corp Mail accounts
- Plaintext passwords stored without encryption
- Login URLs showing exactly which site each password unlocks
Why This Matters
Researchers point out that leaks like this one rarely stay contained to a single site. If any of these 1,075 passwords were reused, attackers can use credential stuffing to reach further accounts, resulting in account takeover well beyond the original leak.
How the Canada Corp Mail Sample Was Built
Investigators trace files like this back to stealer malware, which infects a device and silently copies saved browser passwords along with the matching URL, then sends everything to whoever controls the malware. This "Canada Corp" sample appears to be one batch pulled from that harvest and shared on Telegram.
Check If You Are Affected
HEROIC's free breach scanner lets you check your email against more than 400 billion leaked records identified by analysts, so you can find out quickly whether your credentials are part of this leak or another one.
Breach Breakdown
1,075 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds