The Good_Ads Leak: 2,459 Passwords Exposed. Yours Might Be One.
HEROIC analysts found a stealer log called "Good_Ads 17_doz_p3" uploaded to a Telegram channel on December 23, 2023. The file exposed 2,459 records tied to U.S. users, including email addresses, plaintext passwords, and the API host URLs those logins connect to.
Why This Leak Is Dangerous
The passwords in this file are stored in plaintext, so anyone who downloads it can use the credentials immediately, with no cracking needed. Each password is paired with the specific API URL it unlocks, giving an attacker a direct path into whichever service that account belongs to.
What Was Exposed in the Good_Ads Leak
- Email addresses
- Plaintext passwords
- API host URLs tied to each login
Why This Matters
A file of 2,459 working credentials is exactly the kind of data used in credential stuffing attacks, where attackers try the same email and password combination across many other sites. Anyone in this leak who reused a password elsewhere is at risk of account takeover, and from there, identity theft or financial fraud.
How This Stealer Log Was Created
Stealer logs like "Good_Ads 17_doz_p3" come from malware that infects a device and quietly copies saved passwords, browser autofill data, and login sessions. The stolen data is packaged into a log file and shared or sold on Telegram, exactly how HEROIC found this one on December 23, 2023.
Check If Your Email Was Exposed
If you want to know whether your credentials appear in the Good_Ads log or any other leaked stealer log, HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records. Run a scan now to see if your information has surfaced.
Breach Breakdown
2,459 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds