How Malware Led to 239,835 Stolen Logins in the Brazil 12 Dump
HEROIC uncovered a stealer log collection labeled Brazil 12 on Telegram in February 2023. This substantial dataset focuses on Brazilian users and contains 239,835 records stolen by infostealer malware. Each record captures an email address, a plaintext password, and the URL of the Brazilian or international platform the victim was accessing when the malware extracted their login information.
Nearly 240,000 Passwords Exposed in Plaintext
All 239,835 passwords in the Brazil 12 dataset are stored in their raw, unencrypted form. Attackers who obtain this dataset can read and use every single password without needing to decrypt, crack, or decode anything. At nearly a quarter million records, this is one of the larger Brazil-focused stealer log collections, representing a significant threat to Brazilian internet users whose credentials may still be active and unchanged.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (Brazilian platforms and global services)
Brazilian Users Face Amplified Credential Stuffing Risks
Brazil has one of the largest online populations in the world, and Brazilian users frequently maintain accounts across banking apps, government services like Gov.br, Mercado Livre, iFood, and international platforms. Credential stuffing attacks using the 239,835 pairs from this dump systematically test each combination against all of these services. For users who reuse passwords, a leaked credential from one Brazilian marketplace could lead directly to unauthorized access to their bank account, email inbox, and social media profiles.
The Path From Infection to Telegram Distribution
The Brazil 12 credentials were harvested by infostealer malware that infected Brazilian devices through common vectors: fake WhatsApp updates, pirated software, malicious boleto generators, and phishing campaigns in Portuguese. The malware systematically extracted saved credentials from Chrome, Firefox, and Edge browsers on each infected device. These individual stealer logs were then aggregated, filtered for Brazilian indicators such as .br domains and Portuguese-language services, and compiled into the Brazil 12 collection before being distributed freely on Telegram.
Check If Your Credentials Were Exposed
With 239,835 records focused on Brazilian users, this leak has wide-reaching impact. HEROIC's breach scanner indexes more than 400 billion compromised records from global breaches. Search your email address to determine if your credentials appear in the Brazil 12 dataset or any other known leak, and immediately update your passwords on all services where you use the same login, prioritizing financial and government accounts.
Breach Breakdown
239,835 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds