100 Plaintext Passwords Leaked from Egyptian IP EG156.209.50.108 on Telegram
HEROIC analysts found a stealer log file uploaded to Telegram on March 16, 2025, traced to Egyptian IP address EG156.209.50.108. An anonymous Telegram user shared the file, which contained 100 records with email addresses, plaintext passwords, and URLs harvested directly from infected endpoints. Even at 100 records, a stealer log carrying unencrypted passwords is immediately dangerous, because every single entry is ready to use as a login attempt without any further processing by the attacker.
Why This Is Dangerous
Plaintext passwords require zero effort to exploit. An attacker who downloads this file has 100 working email and password pairs they can start testing agianst popular platforms right away. The URLs in each record act as a roadmap, showing exactly which services the victims were accessing when their credentials were stolen. That removes all guesswork for the attacker and turns a 100-record log into 100 targeted attack vectors.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (websites and services accessed by victims)
Why This Matters
Credential stuffing attacks do not need millions of records to cause serious damage. Even 100 verified plaintext credentials can unlock dozens of accounts if victims reused passwords across multiple sites. From there, attackers can drain bank accounts, take over email inboxes, commit identety theft, and use compromised accounts as launchpads for phishing attacks against the victim's contacts. The EG156.209.50.108 log feeds directly into this cycle the moment it goes live on Telegram.
How Stealer Logs Work
Stealer malware typically spreads through fake downloads, malicious browser extensions, or phishing emails. Once it infects a device, it silently collects every username and password the user types or has saved in their browser, along with the web addresses of the sites they visit. That data gets bundled into a log file and transmitted to the attacker. The log is then shared or sold through channels like Telegram, where large numbers of cybercriminals can access it. The EG prefix in the IP address points to an Egyptian endpoint as the origion of this particular infection, though the victims themselves could be located anywhere the malware spread.
Check If You Are Affected
HEROIC's free breach scanner searches over 400 billion exposed records, including stealer logs like the EG156.209.50.108 file. Enter your email address to find out instantly whether your credentials appeared in this breach or any other known data leak, and get clear steps on what to do next.
Breach Breakdown
100 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds