Social Media Users Exposed: Telegram Stealer Log Leaked 6,944 Facebook Accounts
HEROIC analysts identified a stealer log file uploaded by a Telegram user in August 2023 targeting Facebook-related credentials, exposing 6,944 records. The dataset includes email addresses used to log into Facebook accounts, plaintext passwords, and associated URLs and API endpoint data. This is one of the larger stealer log collections in this series, and because social media accounts serve as identity anchors across the web, the consequences of exposure extend well beyond Facebook itself.
Why This Is Dangerous
Facebook accounts are used for far more than social networking. Millions of people use Facebook Login to authenticate with third-party apps, websites, and services. A compromised Facebook credential does not just expose your social profile: it can hand attackers access to every service you have linked through Facebook Login. Combined with plaintext passwords that require no decryption, this log gives bad actors an immediate entry point to email accounts, shopping platforms, and business tools that rely on Facebook for single sign-on.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Facebook-Related URLs and API Endpoints
Why This Matters
Social media credentials are among the most valuable data types in criminal markets because of their reach. Attackers who gain access to a Facebook account can impersonate the account holder to scam friends and family, use Messenger to distribute phishing links, access Facebook Marketplace to conduct fraud, and harvest personal information for identity theft. For business users, access to a Facebook account linked to a Facebook Business page or Ad account can result in significant financial losses through unauthorized ad spend charged to saved payment methods.
How Stealer Logs Work
Stealer malware is built to prioritize high-value social media credentials. Once installed on a victim's device, the malware searches browser storage for saved Facebook logins, active session cookies, and authentication tokens. These do not just capture the password: they can allow attackers to log into an account even if the password is later changed, as long as the session token remains valid. Facebook-targeted stealer logs are organized and sold separately from other credential categories because they consistently command premium prices on criminal platforms. Sharing them freely on Telegram, as in this case, is a tactic to build reputation and attract buyers for future logs.
Check If You Are Affected
If your email address is linked to a Facebook account, you can check whether it appeared in this stealer log or any other known breach using HEROIC's free scanner. HEROIC's database covers over 400 billion compromised records from thousands of data leaks and criminal data dumps. Check your email now to find out if your Facebook credentials have been exposed, and consider enabling two-factor authentication to protect your account even if your password was captured.
Breach Breakdown
6,944 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds