Breach Intelligence Report 14 Jul 2026

Inside the 100K Stealer Log: 96,973 Passwords Harvested

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs 100k uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 96,973
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts identified a large-scale stealer log titled "100k" that was uploaded to a Telegram channel on July 5, 2026. The dump contains 96,973 records, each including an email address, a plaintext password, and the URLs the victim was browsing when the infostealer malware intercepted their session. This is one of the larger single-file stealer log releases observed on Telegram in recent weeks, representing a substantial trove of exploitable credentials.

The sheer volume of nearly 100,000 records makes this dump a potent weapon for automated credential-stuffing campaigns. Attackers who obtain this file gain access to a massive database of working email-password pairs that can be tested across every major online platform within hours.


Why Plaintext Passwords at This Scale Are Devastating

Every one of the 96,973 passwords in this dump is stored in plaintext, requiring no decryption or cracking. At this scale, the impact is exponential. Automated tools can process tens of thousands of login attempts per hour across multiple platforms simultaneously, meaning the entirety of this dump can be weaponized before most victims even realize their credentials were stolen.

When nearly 100,000 plaintext passwords hit a public Telegram channel, the damage potential is enormous. Each password can be tested against dozens of services, creating millions of login attempts. Financial platforms, email providers, cloud storage services, and social media networks all become targets within minutes of the file being downloaded.


What Was Exposed in the 100K Dump

  • Email Addresses — Nearly 97,000 email accounts spanning multiple providers and regions, each serving as a gateway to the victim's broader online presence.
  • Plaintext Passwords — Unencrypted passwords harvested from browser credential stores, immediately usable for unauthorized access without any technical processing.
  • URLs — The websites and services victims were accessing during the infection, providing attackers with a detailed map of which accounts to target for each victim.

Why 96,973 Credentials Could Compromise Millions of Accounts

At this scale, the mathematics of credential stuffing become staggering. If even 60% of the nearly 97,000 victims reuse their passwords across just three services, that translates to approximately 175,000 additional accounts at risk of takeover. In practice, many users reuse passwords across far more than three platforms, so the actual number of vulnerable accounts could be several times higher.

Large dumps also attract more sophisticated attackers. Organized cybercrime groups monitor Telegram channels for high-volume releases like this one, as the economies of scale make automated exploitation highly profitable. Even a small percentage of successful account takeovers across nearly 100,000 credentials can yield substantial financial returns through fraud, ransom, and data resale.


How Stealer Logs Reach This Massive Scale

A stealer log containing nearly 100,000 records typically represents the aggregated output of a widespread malware campaign. Infostealer malware spreads through phishing emails, malicious advertisements, compromised software downloads, and infected websites. Each infected device contributes credentials for every website the victim has saved passwords for, often dozens of accounts per device.

The malware operates silently, harvesting browser-stored passwords, session cookies, autofill data, and cryptocurrency wallet information. All stolen data is compiled into structured log files and transmitted to the attacker's infrastructure. When these individual logs are combined into a single 100K-record dump, the result is a comprehensive credential database that covers a wide cross-section of internet users and the services they access daily.


Check If Your Credentials Appear in This Leak

With nearly 100,000 records in this dump, the likelihood of any given internet user being affected is higher than with smaller leaks. HEROIC offers a free breach scanner that checks your email address against over 400 billion compromised records from stealer logs, data breaches, and dark web sources.

Search your email address now to find out if your credentials were included in the 100K stealer log or any other known breach. If your information appears, change your passwords immediately across all affected services, enable two-factor authentication on every account that supports it, and consider running a malware scan on your devices to ensure no infostealer is still active.

Breach Breakdown

Domain 100k uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

96,973 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,914 scanned today
Breach Rank #N/A by affected users
Impact Score
4
sensitivity + scale + recency
Est. Financial Impact $701.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance