Hosting Industry Hit: 777,614 cPanel Passwords Leaked
HEROIC uncovered a massive stealer log file titled "1M cPanels" being shared through Telegram channels in November 2025. The dataset contains 777,614 records of compromised credentials specifically targeting cPanel web hosting control panel accounts. This leak is particularly dangerous because cPanel access gives attackers full control over websites, databases, email servers, and file systems hosted on the compromised accounts.
Why Plaintext Passwords to Hosting Panels Are Catastrophic
All 777,614 passwords in this dump are stored in plaintext, meaning attackers can read and use them immediately. When those passwords belong to cPanel accounts rather than ordinary user accounts, the impact is exponentially worse. A compromised cPanel credential does not just give access to one account. It gives an attacker administrative control over entire web servers, allowing them to deface websites, inject malware into pages visited by customers, access databases full of user information, and send spam through the server's email system.
What Was Exposed
- Email Addresses — administrator accounts tied to cPanel hosting management
- Plaintext Passwords — fully readable hosting panel credentials with no encryption
- URLs — the specific cPanel login portals and hosted domains linked to each credential
From Stolen Credentials to Full Server Compromise
Credential stuffing with cPanel credentials is far more damaging than typical account takeovers. Attackers who gain cPanel access can modify website files to insert cryptocurrency miners or phishing pages, access MySQL databases containing customer records, create rogue email accounts for phishing campaigns, and install backdoors that persist even after passwords are changed. The 777,614 compromised credentials in this dump represent hundreds of thousands of potential server-level compromises affecting millions of downstream website visitors.
How Infostealer Malware Harvested These Hosting Credentials
This dataset was produced by infostealer malware infecting the devices of web administrators and hosting account holders. The malware typically spreads through trojanized development tools, pirated software, or phishing emails targeting IT professionals. Once active, it extracts saved credentials from browsers including bookmarked cPanel login pages, captures passwords entered into hosting management interfaces, and steals FTP and SSH credentials stored in local configuration files. The resulting log files are aggregated, labeled by target type, and distributed through underground Telegram channels.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database contains over 400 billion records sourced from data breaches, stealer logs, and dark web marketplaces. Website administrators and hosting account owners should use the HEROIC breach scanner immediately to check whether their credentials appear in the 1M cPanels dump. If your cPanel login is found, change your password immediately, audit your hosted sites for unauthorized modifications, and enable two-factor authentication on all hosting accounts.
Breach Breakdown
777,614 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds