Breach Intelligence Report 15 Jul 2026

i.softbank.jp Leak Means 21,025 Accounts Are Ready to Steal

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs i.softbank.jp uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 21,025
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts have identified a significant stealer log collection targeting i.softbank.jp email users that was uploaded to a public Telegram channel in June 2026. The file contains 21,025 records, each linking a SoftBank mobile email address to a plaintext password and the URL where those credentials were used. The scale of this dump and the specificity of the targeted domain make it a notable threat to Japanese mobile users who rely on SoftBank email services.

With over 21,000 credential pairs now freely circulating, the window for attackers to exploit this data is wide open. Every record in this collection is a working key to at least one online account, and potentially many more.


Why Plaintext Passwords Put Every Linked Account at Risk

The credentials in the i.softbank.jp dump are stored in plaintext — exactly as users originally entered them. Unlike hashed passwords that require computational effort to crack, plaintext passwords can be used instantly. An attacker needs only to copy and paste.

This immediacy transforms the leak from a potential risk into an active threat. Automated credential testing tools can process all 21,025 entries against major online services within hours. For every account where the victim reused their SoftBank email password, the attacker gains access without any additional effort.

SoftBank email accounts themselves are particularly valuable targets. Access to an email inbox enables password resets on virtually every linked service, making one compromised email the gateway to a victim's entire online presence.


What Was Exposed in the i.softbank.jp Dump

  • Email Addresses — SoftBank mobile email addresses (i.softbank.jp), which serve as primary identifiers for many Japanese online services and are tightly integrated with mobile payment and communication platforms.
  • Plaintext Passwords — Unencrypted passwords harvested directly from infected devices, ready for immediate use in account takeover campaigns without any decryption or cracking step.
  • URLs — The specific websites and services where these credentials were entered, providing attackers with a detailed roadmap of each victim's online activity and account portfolio.

Why 21,025 Stolen Credentials Demand Urgent Attention

A leak of this size creates a substantial attack surface. At 21,025 records, this is not a small, easily overlooked dump — it represents a concentrated collection of Japanese mobile users whose credentials are now available to the global cybercriminal community. Credential stuffing operations can leverage this volume to achieve thousands of successful account takeovers.

The economic incentive for attackers is compelling. Compromised accounts connected to mobile carriers often have access to stored payment methods, subscription services, and carrier billing features. A single successful takeover can yield direct financial returns through unauthorized purchases or account resale on dark web marketplaces.

Beyond individual harm, large credential dumps like this feed into aggregated databases used by organized cybercrime groups. The i.softbank.jp records will likely be combined with other leaks to build comprehensive profiles of victims, enabling increasingly sophisticated attacks over time.


How Stealer Logs Extract Credentials From Personal Devices

The 21,025 records in this dump were not obtained by breaching SoftBank's servers. Instead, infostealer malware running on individual devices captured these credentials as users logged into websites and services. The malware intercepts saved passwords from browsers, autofill data, and even keystrokes in real time.

In the Japanese market, infostealers frequently spread through fake mobile applications, compromised download sites, and phishing messages delivered via SMS or messaging apps. Once installed, the malware operates silently while transmitting stolen data to attacker-controlled servers.

The compiled log files are then distributed through Telegram channels and underground forums, where they can be downloaded by anyone. The i.softbank.jp dump likely represents credentials aggregated from hundreds or thousands of individually infected devices, then packaged and shared as a single collection.


Check If Your Credentials Appear in This Leak

If you use an i.softbank.jp email address or have ever logged into services using SoftBank mobile email credentials, you should verify whether your information appears in this dump. With 21,025 records exposed, the probability of any individual SoftBank user being affected is significant.

HEROIC offers a free breach scanner that searches more than 400 billion records from known breaches and stealer log collections worldwide. Enter your email address to check your exposure instantly. If your credentials are found, change your passwords immediately across all affected services and activate two-factor authentication to add a critical layer of protection.

Breach Breakdown

Domain i.softbank.jp uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 15 Jul 2026
Check in 5 seconds

21,025 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,375 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $152.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance