Dark Web Intel: 139,336 Credentials From the 338000 100Private Database Dump
HEROIC analysts intercepted the "338000 100Private" stealer log after it was uploaded to a Telegram channel in August 2023. The dataset contained 139,336 verified records, each including a plaintext password, an email address, and the URL of the site where the credential was stolen. The file name references "100Private," suggesting the content was initially shared within a restricted private channel before broader distribution. Our breach intelligence team confirmed the records as authentic.
Why This Is Dangerous
When a stealer log labeled as "private" starts circulating more widely, the original victims have no idea their credentials just moved from one set of criminal hands to many more. The "100Private" designation likely refers to a private Telegram group where data of this kind is initially sold to select buyers. Once distributed further, the same email-password pairs get tested against banks, streaming services, online retailers, and workplace accounts. With plaintext passwords in hand, there is no extra work for an attacker. The credential works or it does not, and they move through the list fast.
What the 338000 100Private Stealer Log Exposed
Each of the 139,336 records in this breach contained the following information:
- Email addresses (the primary login identifier for the vast majority of online services)
- Plaintext passwords (captured in unencripted form directly from the victim's device or browser)
- URLs (the exact websites where each credential pair was harvested, including internal tools and API enpoints)
Why the 338000 100Private Breach Puts US Users at Serious Risk
The scale of this breach -- nearly 140,000 records -- makes it statistically likely that many of the email addresses appear in other breach datasets as well. Attackers who cross-reference multiple stealer logs can build detailed profiles on individual targets, discovering which services they use, which passwords they reuse, and which accounts are most valuable to compromise. United States users are disproportionately targeted in credential stuffing attacks because so many high-value services -- financial platforms, healthcare portals, e-commerce giants -- are US-centric. Identity theft becomes much easier when an attacker has a verified email, a working password, and a URL that confirms the victim is an active user of a given platform.
How Stealer Logs Like 100Private End Up on the Dark Web
Stealer logs follow a predictable path from infection to criminal marketplace. First, infostealer malware infects a victim's device -- often through a phishing email, a fake software update, or a malicious browser extention. The malware collects saved passwords, cookies, and credentials typed by the user, then sends everything to a remote server controlled by the attacker. The attacker packages the data into a log file named to indicate its origin or volume (in this case, "338000" likely refers to a Telegram channel number and "100Private" indicates the initial distribution tier). The log is first sold or shared in private Telegram channels for a premium, then gradually released more broadly as it loses exclusivety. By the time HEROIC identifies a log, it has often passed through multiple hands and been tested against thousands of services.
Check If Your Accounts Appeared in This Dark Web Breach
The 338000 100Private log is now part of HEROIC's breach intelligence database, which covers over 400 billion compromised records. You can search your email address for free to find out if your credentials were included in this breach or any other known dataset. If your email appears, change the affected password immediately and update it anywhere else you used the same one. Turn on two-factor authentication on your most important accounts. It takes a few minutes and it makes credential stuffing attacks significantly harder to execute.
Breach Breakdown
139,336 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds