Breach Intelligence Report 24 Apr 2026

The Deathmatix Part 2 Log Quietly Appeared on the Dark Web in 2023

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs 15 june logs by deathmatix part 2 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 4,907
Source Type Stealer log
Origin United States
Password Type plaintext

The second installment of the deathmatix log collection appeared on criminal Telegram channels on June 22, 2023, adding 4,907 more victims to an already substantial dataset of stolen credentials. This "part 2" upload continued where the first collection left off, with plaintext passwords, email addresses, and URLs all included in the exposed records. HEROIC analysts have verified this breech as genuine, confirming the credentials are real and have been actively shared across criminal networks. As of today, these credentials have been in criminal hands for nearly three years with little public awareness of their circulation.


Why This Is Dangerous

Stolen credentials distributed on dark web channels get tested against banking, shopping, and cloud platforms within hours of release. Nearly five thousand accounts is a sizable pool from which criminals can extract significant fraudulent value through account takeovers, unauthorized purchases, and identity theft. Victims from this second deathmatix collection face the same elevated risk as those from part one, with the added danger that their data may now appear in multiple aggregated leak databases that have accumulated since the original 2023 release.


What Was Exposed

  • Email Addresses -- Acts as the username for most online accounts and enables targeted phishing campaigns against identified victims.
  • Plaintext Passwords -- Exposed in clear text, meaning no technical skill is needed to use these credentials immediately upon obtaining the dataset.
  • URLs -- Reveals the specific services each victim was logged into, allowing attackers to prioritize targets by value and exploit the most sensitive accounts first.

Why This Matters

When part 2 of the deathmatix collection hit Telegram channels, it was quickly indexed by credential brokers who bundle such logs into larger combo lists for resale on dark web marketplaces. These combo lists are purchased by fraud operators who run automated stuffing attacks against high-value targets including financial institutions and major e-commerce sites. The fact that this data has circulated for nearly three years means it has had extensive opportunity to be tested, verified, and exploited across multiple platforms. Any account where the stolen password was also used elsewhere remains at ongoing risk.


How Stealer Log Attacks Work

A stealer log is created when infostealer malware runs on a victim's device, silently extracting every saved credential it can locate in browsers, password managers, and application data stores. The informaton is transmitted to a remote server controlled by the attacker, often with no outward sign that anything unusual has occured on the infected machine. Threat actors then organize these stolen records by date, source, or quality before distributing them through private Telegram groups and dark web forums. The deathmatix collections represent two separate batches from this kind of large-scale malware operation targeting everyday users.


Check If You Are Affected

HEROIC monitors over 400 billion breached records across thousands of known data leaks, including stealer log distributions from Telegram channels. Visit heroic.com for a free scan to see if your email is in the Deathmatix Part 2 collection or any other breach database. No registration required -- just enter your email and get your results instantly.

Breach Breakdown

Domain 15 june logs by deathmatix part 2 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 24 Apr 2026
Check in 5 seconds

4,907 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #17,826 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $35.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance