The DZ ONLY Dump Dropped in June 2023. The Data Is Still Out There.
On June 11, 2023, a Telegram user uploaded a stealer log file titled DZ ONLY, exposing 841 records of stolen credentials. The name suggests the data was specifically targeted at or collected from users in Algeria (DZ is Algeria's international country code), making this a geographically focused credential dump. But breach data does not respect borders -- once a file is uploaded to Telegram, it spreads far beyond the original channel, copied and redistributed across dozens of groups and archives. That original upload happened over two years ago, and the data from DZ ONLY is almost certainly still circulaing in criminal networks today, being used and reused long after the initial leak.
Why This Is Dangerous
The danger of stealer logs like DZ ONLY does not expire with time. Because the credentials are stored in plaintext, they remain immediately usable for as long as victims have not changed their passwords. Many people are never notified that their data was exposed, so they continue using compromised credentials for months or years after a breach. With 841 records from the original DZ ONLY dump now potentially scattered across multiple Telegram archives and dark web forums, the number of people who have accessed this data is impossible to count. Every day that passes without a password change is another day of exposure for the victoms in this file.
What Was Exposed
- Email Addresses
- Plaintext Passwords (unencrypted, no cracking needed)
- URLs (showing exactly which services each victim used)
Why This Matters
Stealer logs that target specific regions or demographics are particularly valuable to cybercriminals because they allow for focused attacks. A file labeled DZ ONLY tells a criminal exactly which region's users and services to target, enabling more convincing phishing follow-ups in the local language and against locally popular platforms. Even though the breach happened in June 2023, the risks compound over time as the data passes through more hands. Each new person who downloads the file is a new potential attacker with immediate access to 841 sets of working credentials. Breach data from 2023 remains dangerous in 2026 because most exposed users have never been alerted and have made no changes to their compromised accounts.
How Stealer Log Malware Works
The DZ ONLY log was assembled by stealer malware running on infected computers. Stealers are typically delivered through phishing emails, fake software downloads, and malicious browser extensions. Once active on a machine, the malware extracts every saved password from installed browsers including Chrome, Firefox, and Edge, and also harvests credentials from standalone applications like FTP clients, VPN software, and email clients. The compiled credential file is sent to the attacker's server and then packaged into log batches for distribution. Regional targeting -- as the DZ ONLY name implies -- can occur when attackers target specific IP ranges or language settings during their infection campaigns, or when they sort harvested data by geolocation after the fact before uploading to Telegram channels.
Check If You Are Affected
Even though the DZ ONLY dump was uploaded more than two years ago, the threat is very much present today. HEROIC's free scanner searches more than 400 billion exposed records, including historical stealer logs like DZ ONLY that continue to circulatte in criminal networks. Enter your email address to find out immediately if your credentials are among the 841 exposed in this breach. If your data is found, change your passwords now -- starting with your email, then any banking, work, or social accounts where you reused the same password. Check your exposure free at HEROIC today.
Breach Breakdown
841 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds