How Malware Led to 503,246 Stolen Logins in the Mixed Domains Dump
HEROIC identified a massive stealer log collection labeled 503k Mixed Domains on Telegram in February 2023. Spanning an enormous range of websites and services, this dataset contains 503,246 records stolen by infostealer malware from thousands of infected devices. Each record pairs an email address with a plaintext password and the specific URL where the credentials were intercepted.
Half a Million Plaintext Passwords Available to Attackers
With 503,246 passwords stored in plaintext, this is one of the larger stealer log datasets HEROIC has cataloged. Every single password can be read and used immediately without any decryption or cracking. The sheer volume means that even a modest success rate in account takeover attempts would yield thousands of compromised accounts, making this dataset highly attractive to cybercriminals running large-scale credential exploitation campaigns.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (mixed domains across hundreds of different services)
Mixed Domains Multiply the Credential Stuffing Threat
Because this dataset spans mixed domains rather than targeting a single service, it provides attackers with a broad cross-section of credentials. Credential stuffing campaigns using this data can test logins against banking sites, email platforms, corporate VPNs, healthcare portals, and social media networks all at once. The diversity of domains also means that victims who appear in this dataset may have multiple accounts exposed across entirely different services, dramatically increasing their overall risk.
The Infostealer Pipeline: From Infection to Telegram
The 503,246 records in this dataset represent the output of an infostealer malware operation that compromised devices on a significant scale. The malware, once installed through phishing emails, trojanized software, or drive-by downloads, systematically extracted saved credentials from every browser on the infected machine. The harvested data was organized into logs, aggregated across victims, and then uploaded to Telegram as a consolidated mixed-domain collection. This pipeline operates continuously, with new log files appearing on a near-daily basis.
Check If Your Credentials Were Exposed
With 503,246 records spanning hundreds of different websites, the probability of your credentials appearing in this dataset increases if you use many online services. HEROIC's breach scanner indexes over 400 billion compromised records. Search your email address to determine if your credentials are part of this mixed domains dump or any other known leak, and prioritize changing passwords for your most sensitive accounts first.
Breach Breakdown
503,246 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds