Dark Web Intel: 710 ex.ua Passwords Found in Stealer Log Dump
What HEROIC Analysts Found
In June 2026, HEROIC analysts tracked a stealer log circulating on Telegram containing 710 records tied to the domain ex.ua, based in Ukraine. The log contained email addresses, plaintext passwords, and the login URLs those credentials open. While smaller than some of the other logs analysts have reviewed this month, every record in a log like this represents a real infected device and a real working login.
Dark Web Intel: Why Small Logs Still Matter
It's tempting to assume a leak of 710 records is too small to worry about, but dark web monitoring shows that small stealer logs are routinely folded into much larger combolists that criminals build over time. A modest log today can end up as one slice of a database with millions of entries, searchable by domain, meaning the size of the original leak says little about how long the exposure will last or how widely it will spread.
What Was Exposed
- Email addresses
- Plaintext (unencrypted) passwords
- Login URLs tied to each set of credentials
Why This Matters
Because the passwords in this log are plaintext, they are ready to use the moment someone downloads the file. Anyone who reused their ex.ua password elsewhere is at risk of credential stuffing, where the same login is tried automatically across other accounts. If the email is also used as a personal inbox, a working password can be used to reset other accounts, extending the damage beyond the original login.
How Stealer Logs Like This Get Onto Telegram
This data comes from infostealer malware, malicious software that infects a device, often through a pirated download or fake installer, and quietly harvests saved browser passwords, autofill entries, and active sessions. The results are compiled into a log file and posted to dark web forums and Telegram channels, where analysts and criminals alike monitor for newly leaked domains and credentials.
Check If You Are Affected
If you have an account tied to ex.ua, it's worth checking whether your credentials are part of this leak. HEROIC's free breach scanner checks your email against a database of more than 400 billion exposed records pulled from dark web sources, including stealer logs like this one, so you can find out in seconds.
Breach Breakdown
710 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds