eclipse1.net Data Breach: 3,325 Passwords Found in Telegram Leak
What HEROIC Analysts Found
In June 2026, HEROIC analysts found a stealer log uploaded to a Telegram channel containing 3,325 records tied to the domain eclipse1.net. The log contained email addresses, plaintext passwords, and the login URLs those credentials open. This information was not stolen from a company's servers directly. It was collected from individual infected devices and bundled into a single file for distribution.
Why This Is Dangerous
An email address by itself tells an attacker little. A password without context tells them even less. But this log pairs both with the exact login URL they belong to, which means an attacker can go straight to the account and log in without guessing, cracking, or phishing first. That combination is what makes stealer logs more immediately dangerous than a list of emails or passwords alone.
What Was Exposed
- Email addresses
- Plaintext (unencrypted) passwords
- Login URLs tied to each set of credentials
Why This Matters
Because these passwords are stored in plaintext, no extra effort is required to use them. Anyone who reused an eclipse1.net password on another account faces a real risk of credential stuffing, where the same login is tested automatically across banking, email, and shopping sites. If the exposed email is used elsewhere as a recovery address, a single working login can be leveraged into a broader account takeover.
How Stealer Logs Like This One Are Built
This leak traces back to infostealer malware, a type of malicious software that infects a device, often through a fake download or cracked application, and then quietly scans the browser for saved passwords, autofill entries, and open sessions. Everything it finds is compiled into a log file and shared on Telegram, sometimes for free and sometimes for sale. From there, criminals combine many logs into searchable collections, making it simple to pull out every credential tied to a specific domain like eclipse1.net.
Check If You Are Affected
If you have an account tied to eclipse1.net, it's worth checking whether your credentials appear in this leak. HEROIC's free breach scanner checks your email against a database of more than 400 billion exposed records, including stealer logs like this one, so you can find out in seconds and update any reused passwords before someone else does.
Breach Breakdown
3,325 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds