The Ethiopia Corp Mail Breach Put 1,064 Passwords Online
In February 2026, HEROIC analysts identified a stealer log labeled "ETHIOPIA CORP-OTHERS-PRO MAILS TEST SAMPLE" shared on Telegram, containing 1,064 records of email addresses, plaintext passwords, and login URLs pulled from infected devices.
Why This Is Dangerous
Each of the 1,064 records pairs a working email with its plaintext password and the exact site it unlocks, meaning anyone with this file can log straight into the accounts it lists, no cracking required.
What Was Exposed
- Email addresses tied to the affected Ethiopia Corp Mail accounts
- Plaintext passwords with no encryption
- Login URLs showing which site each password opens
Why This Matters
Reused passwords are the biggest risk here, since attackers can take any of these 1,064 credentials and try them across other websites through credential stuffing, potentially leading to account takeover on services that were never part of the original leak.
How the Ethiopia Corp Mail Sample Was Built
Stealer malware quietly copies saved browser passwords and their matching URLs from an infected device, then sends the data back to whoever controls the malware. This "Ethiopia Corp" sample is a batch pulled from that kind of harvest and shared for other criminals to browse on Telegram.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion leaked records, so you can find out in seconds whether your credentials are part of this leak or another one, and change any exposed passwords right away.
Breach Breakdown
1,064 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds