HEROIC Analysts Discover 104,829 Exposed Logins in the 118k Leak
While combing through newly posted files on Telegram, HEROIC analysts came accross a stealer log simply named 118k. Despite the rounded name, the actual count came in at 104,829 records, each containing an email, a plaintext password, and the site it belonged to, all dated back to January 2026.
Why This Is Dangerous
Files with vague, shorthand names like this one are easy to overlook, but that doesn't make them any less dangerous. The 104,829 records inside are just as usable as anything found in a bigger, more famous leak. A criminal doesn't care what the file is called, only that the logins inside still work.
What Was Exposed
- Email Addresses
- Plaintext Password
- URLs
- 104,829 total records exposed
Why This Matters
Discoveries like this one matter because so many stealer logs never get formally documented or reported. Once HEROIC analysts flag a file like the 118k dump, the records inside can be added to breach monitoring tools, giving people a chance to find out and respond before their accounts get taken over.
How Stealer Logs Work
This kind of leak begins with malicious software running quietly on someone's device, reading saved passwords straight out of the browser and pairing each one with its matching website. The data gets bundled into a log file, given a short internal name for easy reference, and eventually shared or sold on Telegram, wich is exactly where analysts found this one.
Check If You Are Affected
You don't have to rely on analysts finding your data by chance. Use HEROIC's free breach scanner to check your own email against a database of more than 400 billion leaked records and see instantly if you show up in this leak or any other.
Breach Breakdown
104,829 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds