Breach Intelligence Report 14 Nov 2025

IN103.186.41.222 uploaded by a Telegram User

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 635
Source Type Stealer log
Origin Telegram
Password Type plaintext

We noticed a concerning upload on December 27, 2024, originating from a Telegram user, which contained a stealer log file. This particular log, identified by the IP address IN103.186.41.222, exposed a relatively small but highly sensitive dataset. What struck us was the direct exposure of plaintext passwords alongside email addresses and associated API host URLs, a combination that dramatically lowers the barrier to entry for further compromise. The relatively low pwned count of 635 records belies the potential impact given the nature of the exposed credentials.

The breach originated from a stealer log, a common artifact of malware designed to exfiltrate credentials and other sensitive information from compromised endpoints. The log, uploaded to Telegram, contained 635 records. Each record detailed an endpoint, an associated email address, the API host URL, and critically, plaintext passwords. This direct exposure of credentials, rather than hashed or encrypted forms, represents a significant risk. The threat theme here is straightforward credential stuffing and unauthorized access, where attackers can leverage these directly usable credentials to gain access to other systems or services, especially if users have reused passwords. The source structure indicates a direct dump from an infected system, bypassing typical network defenses and highlighting endpoint security as a critical vulnerability.

While this specific incident does not appear to have generated widespread news coverage, the broader trend of stealer malware remains a persistent threat. Numerous cybersecurity research firms, including Mandiant and CrowdStrike, regularly publish reports detailing the prevalence and evolving tactics of information-stealing malware. OSINT investigations frequently uncover similar leaks on dark web forums and public file-sharing platforms, underscoring the ongoing challenge of preventing credential exfiltration. The presence of API host URLs alongside credentials suggests a potential for attackers to target specific service accounts, further amplifying the risk beyond individual user accounts.

We observed a significant data leak on December 20, 2024, attributed to a breach of the "GlobalConnect" platform. The discovery was made through routine monitoring of dark web marketplaces, where a seller advertised a substantial dataset. What immediately stood out was the sheer volume of personally identifiable information (PII) and financial data, coupled with the platform's critical role in managing user access for multiple downstream services. The exposed records paint a picture of a comprehensive compromise, impacting a wide array of user data categories. This incident warrants immediate attention due to the potential for widespread identity theft and financial fraud.

The "GlobalConnect" breach, discovered on December 20, 2024, involved the exfiltration of approximately 1.2 million records. The leaked data encompasses a broad spectrum of sensitive information, including full names, email addresses, physical addresses, phone numbers, dates of birth, and partial credit card numbers (last four digits and expiry dates). Additionally, the dataset includes hashed passwords, which, while not directly usable, can be vulnerable to brute-force attacks if weak hashing algorithms were employed or if the platform reused credentials. The source structure appears to be a direct database dump, indicating a successful intrusion into GlobalConnect's core infrastructure. The leak locations were primarily identified on a private Telegram channel and subsequently mirrored on several dark web forums, suggesting a coordinated effort to monetize the stolen data. The threat theme is multifaceted, ranging from identity theft and financial fraud to account takeovers and targeted phishing campaigns leveraging the detailed PII.

This "GlobalConnect" breach has garnered significant attention in the cybersecurity community. Reports from KrebsOnSecurity and The Hacker News have detailed the incident, highlighting the scale of the PII exposed. Further OSINT analysis has revealed that GlobalConnect is a third-party vendor used by numerous enterprises, meaning this single breach could have downstream implications for many organizations that relied on their services. Research from security firms like Recorded Future has consistently flagged GlobalConnect as a potential target due to its central role in managing user identities and access credentials across various sectors.

We identified an unusual network traffic pattern on December 15, 2024, originating from a compromised IoT device within our managed network. The subsequent investigation revealed a sophisticated watering hole attack that had successfully infected a small but critical segment of our employee workstations. What was particularly alarming was the stealthy nature of the malware, which evaded initial signature-based detection and employed novel obfuscation techniques. The attack chain demonstrated a clear intent to target specific internal resources, suggesting a highly targeted and persistent threat actor.

The incident, detected on December 15, 2024, involved a watering hole attack that leveraged a zero-day vulnerability in a widely used web browser plugin. The attack chain began with the compromise of a publicly accessible website frequented by our employees, which was then retrofitted with malicious code. Upon visiting the compromised site, targeted workstations were infected with a custom-designed malware. Analysis of the malware revealed it was designed to exfiltrate internal network diagrams, employee contact lists, and sensitive project documentation. While the exact number of infected endpoints is still under investigation, initial estimates suggest around 50 workstations were compromised. The data types exposed are primarily intellectual property and internal operational intelligence. The source structure of the malware indicates a sophisticated development process, likely by a well-resourced threat actor group. The leak locations are currently unknown, as the malware appears to be designed for persistent access and data exfiltration rather than immediate public disclosure, suggesting a focus on espionage or strategic disruption.

While this specific incident remains largely internal, the underlying attack vector is consistent with trends observed by major cybersecurity agencies. Reports from CISA and ENISA have repeatedly warned about the increasing sophistication of watering hole attacks and the exploitation of zero-day vulnerabilities. OSINT investigations into similar attack methodologies have pointed towards nation-state sponsored or highly organized cybercriminal groups. The use of custom malware and advanced obfuscation techniques aligns with the tactics, techniques, and procedures (TTPs) documented in threat intelligence reports from companies like Palo Alto Networks and FireEye, indicating a high level of operational security and technical proficiency from the attackers.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Nov 2025
Check in 5 seconds

635 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #22,584 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $4.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance