The DE 6.11 Dump: 90,932 Stolen Login Credentials Hit the Dark Web
HEROIC Analysts Uncover the DE 6.11 Stealer Log
HEROIC's threat intelligence team identified a large stealer log titled "DE 6.11" uploaded to Telegram by an anonymous user, dated January 18, 2023. The file contained 90,932 records, each pairing an email address with a plaintext password and the URL of the login page the credentials were used on.
The DE 6.11 Dump: 90,932 Stolen Login Credentials Hit the Dark Web
A file of this size is rarely the work of a single infected machine. Logs like DE 6.11 are typically assembled from many separate malware infections, then combined and labeled before being circulated. Each of the 90,932 entries represents a real, working login at the moment it was captured, giving whoever holds the file an enormous list of accounts they can attempt to access directly.
What Was Exposed in the DE 6.11 Log
- Email addresses used to log into online accounts
- Plaintext passwords tied to those accounts
- The website URLs each credential pair was used on
Why This Matters for the 90,932 People in This Log
At this scale, the biggest danger is automation. Criminals feed lists like DE 6.11 into credential stuffing tools that test every email and password combination against popular websites within seconds, catching anyone who reused a password across accounts. That can lead to compromised email, banking, or shopping accounts for a huge number of people who have no idea their information was ever exposed.
How a Stealer Log This Size Gets Assembled
This data comes from infostealer malware, which infects devices through phishing emails, cracked software, or malicious ads, then silently harvests saved browser passwords and autofill details. Large compiled releases like DE 6.11 combine the output of many infections into a single file before being shared or sold on Telegram channels built around trading stolen credentials.
Check If You Are Affected
With over 90,000 records in a single log, the odds that your information appears somewhere in a stealer dump are real. HEROIC's free breach scanner checks your email against a database of more than 400 billion compromised records, so you can quickly find out and secure any accounts still using an exposed password.
Breach Breakdown
90,932 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds