i.softbank.jp Leak Means 21,025 Accounts Are Ready to Steal
HEROIC analysts have identified a significant stealer log collection targeting i.softbank.jp email users that was uploaded to a public Telegram channel in June 2026. The file contains 21,025 records, each linking a SoftBank mobile email address to a plaintext password and the URL where those credentials were used. The scale of this dump and the specificity of the targeted domain make it a notable threat to Japanese mobile users who rely on SoftBank email services.
With over 21,000 credential pairs now freely circulating, the window for attackers to exploit this data is wide open. Every record in this collection is a working key to at least one online account, and potentially many more.
Why Plaintext Passwords Put Every Linked Account at Risk
The credentials in the i.softbank.jp dump are stored in plaintext — exactly as users originally entered them. Unlike hashed passwords that require computational effort to crack, plaintext passwords can be used instantly. An attacker needs only to copy and paste.
This immediacy transforms the leak from a potential risk into an active threat. Automated credential testing tools can process all 21,025 entries against major online services within hours. For every account where the victim reused their SoftBank email password, the attacker gains access without any additional effort.
SoftBank email accounts themselves are particularly valuable targets. Access to an email inbox enables password resets on virtually every linked service, making one compromised email the gateway to a victim's entire online presence.
What Was Exposed in the i.softbank.jp Dump
- Email Addresses — SoftBank mobile email addresses (i.softbank.jp), which serve as primary identifiers for many Japanese online services and are tightly integrated with mobile payment and communication platforms.
- Plaintext Passwords — Unencrypted passwords harvested directly from infected devices, ready for immediate use in account takeover campaigns without any decryption or cracking step.
- URLs — The specific websites and services where these credentials were entered, providing attackers with a detailed roadmap of each victim's online activity and account portfolio.
Why 21,025 Stolen Credentials Demand Urgent Attention
A leak of this size creates a substantial attack surface. At 21,025 records, this is not a small, easily overlooked dump — it represents a concentrated collection of Japanese mobile users whose credentials are now available to the global cybercriminal community. Credential stuffing operations can leverage this volume to achieve thousands of successful account takeovers.
The economic incentive for attackers is compelling. Compromised accounts connected to mobile carriers often have access to stored payment methods, subscription services, and carrier billing features. A single successful takeover can yield direct financial returns through unauthorized purchases or account resale on dark web marketplaces.
Beyond individual harm, large credential dumps like this feed into aggregated databases used by organized cybercrime groups. The i.softbank.jp records will likely be combined with other leaks to build comprehensive profiles of victims, enabling increasingly sophisticated attacks over time.
How Stealer Logs Extract Credentials From Personal Devices
The 21,025 records in this dump were not obtained by breaching SoftBank's servers. Instead, infostealer malware running on individual devices captured these credentials as users logged into websites and services. The malware intercepts saved passwords from browsers, autofill data, and even keystrokes in real time.
In the Japanese market, infostealers frequently spread through fake mobile applications, compromised download sites, and phishing messages delivered via SMS or messaging apps. Once installed, the malware operates silently while transmitting stolen data to attacker-controlled servers.
The compiled log files are then distributed through Telegram channels and underground forums, where they can be downloaded by anyone. The i.softbank.jp dump likely represents credentials aggregated from hundreds or thousands of individually infected devices, then packaged and shared as a single collection.
Check If Your Credentials Appear in This Leak
If you use an i.softbank.jp email address or have ever logged into services using SoftBank mobile email credentials, you should verify whether your information appears in this dump. With 21,025 records exposed, the probability of any individual SoftBank user being affected is significant.
HEROIC offers a free breach scanner that searches more than 400 billion records from known breaches and stealer log collections worldwide. Enter your email address to check your exposure instantly. If your credentials are found, change your passwords immediately across all affected services and activate two-factor authentication to add a critical layer of protection.
Breach Breakdown
21,025 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds