Dark Web Intel: 12.3 Million Credentials From the Telegram URL Login Pass Dump
HEROIC analysts identified a large-scale stealer log file uploaded to Telegram in April 2025 that exposed 12,354,993 records. The dataset, titled "17 500 000 URL LOGIN PASS," was distributed by an anonymous Telegram user and contained email addresses, plaintext passwords, and endpoint URLs harvested from infected devices worldwide. At over 12 million records, this represents one of the larger single-file credential dumps to surface through Telegram distribution channels in 2025.
Why This Telegram Credential Dump Is Dangerous
This is not a list of hashed passwords that require cracking. Every password in this file is in plaintext, meaning anyone who downloads it can immediately attempt to log into the associated accounts. The inclusion of endpoint URLs means attackers can see exactly which services each victim was using, allowing them to prioritze high-value targets like banking portals, email providers, and corporate VPNs. With 12 million records, even a small percentage of successful logins translates to hundreds of thousands of compromised accounts.
Data Exposed in the Telegram URL Login Pass Dump
The following categories of data were confirmed in this stealer log file:
- Email Addresses (usernames for account access)
- Plaintext Passwords (unencrypted, ready to use)
- URLs (the specific services and websites victims were logged into)
How Criminals Use 12 Million Stolen Credentials
A dataset of this size enables industrialised credential abuse at scale. Here is what happens to files like this after they are shared on Telegram:
- Credential stuffing: Automated attack tools cycle through all 12 million pairs against major platforms simultaneously, exploiting password reuse across services.
- Account takeover: Once inside an account, attackers lock out the owner, harvest connected payment methods, and mine the inbox for additional accounts to compromise.
- Identity theft: Email access exposes full name, address, purchase history, and government ID documents stored with connected services, enabling fraudulent applications in the victum's name.
- Financial fraud: Banking URLs in the dump tell attackers exactly which financial institutions to target for direct account draining or loan fraud.
What Is a Telegram Stealer Log Dump and Where Does It Come From
Stealer logs originate from infostealer malware infections on individual devices. Malware families like RedLine, Raccoon Stealer, and Vidar infect machines through phishing links, cracked software, and malicious browser extensions. Once running, they extract all saved passwords, session cookies, and browser autofill data within minutes, then upload everything to the attacker's server. Operators then compile thousands of individual device logs into large files, which are sold or freely shared in Telegram channels. The "17 500 000 URL LOGIN PASS" naming convention is typical of these bulk credential dumps, reflecting the attacker's advertised record count before final deduplication. These files circulate widely, meaning any number of threat actors may have already acted on this data since it was posted in April 2025.
Find Out If Your Credentials Were Exposed
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including Telegram stealer log dumps like this one. If your login appeared in this file or any other breach in our database, you will know instantly and can take action before your accounts are accessed. Scan your email for free at HEROIC now.
Breach Breakdown
12,354,993 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds