The Good_Ads_doz_p1 Log Quietly Surfaced With 2,144 Stolen Logins
HEROIC analysts found a stealer log called "Good_Ads_doz_p1" quietly uploaded to a Telegram channel on December 23, 2023. The file exposed 2,144 records tied to U.S. users, including email addresses, plaintext passwords, and the API host URLs those credentials belong to.
Why This Leak Is Dangerous
Nothing about this upload made headlines, but the data inside is just as usable as any high-profile breach. Every password was stored in plaintext, so anyone who finds the file can log in immediately, and each password is already matched to the exact web address it unlocks.
What Was Exposed in the Good_Ads_doz_p1 Log
- Email addresses
- Plaintext passwords
- API host URLs tied to each login
Why This Matters
Small, quiet leaks like this one are exactly the kind of data used in credential stuffing, where attackers test stolen logins against other sites hoping for password reuse. Anyone in this file of 2,144 people faces a real risk of account takeover, and the identity theft or fraud that can follow.
How Stealer Logs Like This One Get Made
Stealer logs come from malware that infects a device and silently harvests saved passwords, browser autofill entries, and login sessions. The results are bundled into a file, like the one named "Good_Ads_doz_p1," and then shared or sold on Telegram, exactly how HEROIC found this one on December 23, 2023.
Check If Your Email Was Exposed
If you want to know whether your credentials appear in the Good_Ads_doz_p1 log or any other leaked stealer log, HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records. Run a scan now to see if your information has surfaced.
Breach Breakdown
2,144 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds