The Deathmatix Part 2 Log Quietly Appeared on the Dark Web in 2023
The second installment of the deathmatix log collection appeared on criminal Telegram channels on June 22, 2023, adding 4,907 more victims to an already substantial dataset of stolen credentials. This "part 2" upload continued where the first collection left off, with plaintext passwords, email addresses, and URLs all included in the exposed records. HEROIC analysts have verified this breech as genuine, confirming the credentials are real and have been actively shared across criminal networks. As of today, these credentials have been in criminal hands for nearly three years with little public awareness of their circulation.
Why This Is Dangerous
Stolen credentials distributed on dark web channels get tested against banking, shopping, and cloud platforms within hours of release. Nearly five thousand accounts is a sizable pool from which criminals can extract significant fraudulent value through account takeovers, unauthorized purchases, and identity theft. Victims from this second deathmatix collection face the same elevated risk as those from part one, with the added danger that their data may now appear in multiple aggregated leak databases that have accumulated since the original 2023 release.
What Was Exposed
- Email Addresses -- Acts as the username for most online accounts and enables targeted phishing campaigns against identified victims.
- Plaintext Passwords -- Exposed in clear text, meaning no technical skill is needed to use these credentials immediately upon obtaining the dataset.
- URLs -- Reveals the specific services each victim was logged into, allowing attackers to prioritize targets by value and exploit the most sensitive accounts first.
Why This Matters
When part 2 of the deathmatix collection hit Telegram channels, it was quickly indexed by credential brokers who bundle such logs into larger combo lists for resale on dark web marketplaces. These combo lists are purchased by fraud operators who run automated stuffing attacks against high-value targets including financial institutions and major e-commerce sites. The fact that this data has circulated for nearly three years means it has had extensive opportunity to be tested, verified, and exploited across multiple platforms. Any account where the stolen password was also used elsewhere remains at ongoing risk.
How Stealer Log Attacks Work
A stealer log is created when infostealer malware runs on a victim's device, silently extracting every saved credential it can locate in browsers, password managers, and application data stores. The informaton is transmitted to a remote server controlled by the attacker, often with no outward sign that anything unusual has occured on the infected machine. Threat actors then organize these stolen records by date, source, or quality before distributing them through private Telegram groups and dark web forums. The deathmatix collections represent two separate batches from this kind of large-scale malware operation targeting everyday users.
Check If You Are Affected
HEROIC monitors over 400 billion breached records across thousands of known data leaks, including stealer log distributions from Telegram channels. Visit heroic.com for a free scan to see if your email is in the Deathmatix Part 2 collection or any other breach database. No registration required -- just enter your email and get your results instantly.
Breach Breakdown
4,907 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds