Website Admins Targeted: the goodFTPs File Exposed 18 FTP Logins
FTP credentials aren't aimed at everyday shoppers, they're aimed at the people who run websites. That's exactly what sits inside goodFTPs, a file originally dated October 2023 but still circulating on Telegram, holding 18 email and password pairs tied to FTP server access. Every password is stored in plain text alongside the login URL. If you manage a website or server, scanning your email is the way to check whether you're one of the 18.
Why Website Administrators Are the Target Here
FTP access is how site files get uploaded and changed, which makes it far more valuable to an attacker than an ordinary shopping or social login. A working FTP credential can mean direct access to an entire website's backend.
What Was Exposed
- Email addresses: identify the account tied to each of the 18 FTP logins.
- Plaintext passwords: readable and usable immediately, no cracking required.
- URLs: point to the exact server each credential connects to.
What Happens if a Site Admin Is Affected
With working FTP access, an attacker can modify site files directly, plant malicious code, or redirect visitors elsewhere, all without ever needing to touch the website's front end login.
How a File Like goodFTPs Gets Built
These credentials are typically gathered from stolen data tied to server and hosting logins, then filtered down to confirmed, working FTP accounts before being shared as a smaller, targeted file.
Are You Managing One of These 18 Servers?
Scan your email to check. If your address is listed, change the FTP password immediately from a device you trust, and review your server for any files you don't recognize. This matters whether the account is for personal projects or client work.
Breach Breakdown
18 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds