How Malware Led to 43 Stolen B2B Logins in the Anonrise0 Dump
HEROIC identified a stealer log collection labeled "United States B2B SampleDM Anonrise0" that was shared in September 2025. This dump contains 43 records specifically targeting U.S. business-to-business accounts. Each entry links an email address to a plaintext password and the URL of the service where the credential was stolen. The B2B designation and "SampleDM" label suggest this is a preview of a larger business-focused credential collection being marketed by the Anonrise0 threat actor.
Plaintext Business Passwords: A Corporate Security Nightmare
All 43 passwords in this dump are stored in plaintext, giving anyone who accesses the file instant entry to business accounts. Corporate credentials are particularly high-value targets because they often grant access to sensitive company data, customer databases, financial systems, and internal communications. A single compromised B2B password can open the door to an entire organization's infrastructure.
What Was Exposed
- Email Addresses — business email accounts belonging to U.S. organizations
- Plaintext Passwords — unencrypted corporate credentials with immediate access potential
- URLs — business platforms, portals, and services where these credentials were in active use
B2B Credentials Enable Enterprise-Level Attacks
Unlike consumer credential dumps, B2B credentials provide entry into corporate environments where the stakes are exponentially higher. Attackers who gain access through a stolen business login can pivot laterally within an organization, access customer data, initiate wire transfers, or deploy ransomware. With 43 targeted B2B credentials, even this small sample could enable business email compromise schemes worth hundreds of thousands of dollars per successful attack.
The Anonrise0 Threat Actor and Infostealer Operations
The Anonrise0 handle identifies a threat actor distributing curated credential sets through Telegram. The "SampleDM" designation indicates this is a sample package — a preview designed to attract buyers for larger business credential databases. The underlying data was collected by infostealer malware that infected business users' devices, extracting saved credentials from corporate browsers, VPN clients, and business applications. This malware specifically targets corporate environments where a single compromised endpoint can yield access to an entire organization's cloud services and internal tools.
Check If Your Credentials Were Exposed
With over 400 billion records in its breach intelligence database, HEROIC provides comprehensive coverage of both consumer and business credential leaks. Search your business email address using HEROIC's breach scanner to determine if your account was included in the Anonrise0 B2B dump or any other known compromise, and alert your IT security team immediately if your corporate credentials are found.
Breach Breakdown
43 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds