The Estonia Corp Mail Dump: 1,056 Stolen Logins Hit the Dark Web
In February 2026, HEROIC analysts found a stealer log labeled "ESTONIA CORP-OTHERS-PRO MAILS TEST SAMPLE" circulating on Telegram. It contained 1,056 records of email addresses, plaintext passwords, and login URLs, taken from infected devices rather than a company breach.
Why This Is Dangerous
Each record already includes a working email, its plaintext password, and the exact site it unlocks. There's no cracking involved, so whoever holds this file can start logging into the accounts it lists right away.
What Was Exposed
- Email addresses tied to the affected Estonia Corp Mail accounts
- Plaintext passwords stored without encryption
- Login URLs identifying exactly which site each password opens
Why This Matters
If any of these 1,056 passwords were reused on other sites, attackers can use them for credential stuffing, potentially leading to account takeover on banking, shopping, or social accounts that had nothing to do with the original infection.
How the Estonia Corp Mail Dump Was Created
Stealer malware infects a device, silently copies saved browser passwords along with their matching URLs, and sends everything back to whoever controls the malware. This "Estonia Corp" dump is a batch drawn from that kind of harvest and shared on Telegram for other criminals to search.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion leaked records, including logs like this one, so you can quickly check your email and change any password that has already been exposed.
Breach Breakdown
1,056 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds