Breach Intelligence Report 14 Jul 2026

Inside the Corps 12.01 Stealer Logs: 72,796 Passwords Harvested

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Corps 12.01 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 72,796
Source Type Stealer log
Origin United States
Password Type plaintext

In April 2023, HEROIC analysts cataloged a stealer log distributed through Telegram under the designation "Corps 12.01." Technical analysis of the dataset revealed 72,796 unique records, each containing an email address, a plaintext password, and the URL of the service where the credential was stored. The structured format and naming convention suggest this log was part of a larger, organized collection effort by a threat actor or distribution group.


Why Plaintext Credentials Require No Cracking to Exploit

The passwords in the Corps 12.01 dataset are stored in plaintext rather than as hashed or encrypted values. From a technical standpoint, this eliminates the most resource-intensive step in credential exploitation. Attackers do not need GPU clusters, rainbow tables, or brute-force tools. Each email-password pair is immediately usable as-is against the corresponding login endpoint.

Plaintext extraction occurs because infostealer malware reads credentials directly from browser password stores, which decrypt saved passwords on the local device. The malware captures them after the browser has already performed decryption, so the resulting log contains the exact characters the user typed. This means the credentials in Corps 12.01 are not approximations or partial matches. They are the actual passwords.

For defenders and affected users, this distinction matters. There is no grace period during which passwords might remain safe while an attacker attempts to crack a hash. Exposure is immediate and complete from the moment the log is shared.


What Was Exposed in the Corps 12.01 Dump

  • Email Addresses — The primary login identifiers extracted from browser autofill and saved credential stores, representing verified accounts across a range of online services and platforms.
  • Plaintext Passwords — The exact passwords as stored in victim browsers, captured post-decryption by the infostealer, providing direct and immediate access to each corresponding account.
  • URLs — The specific service endpoints and login pages tied to each credential pair, enabling attackers to automate targeted login attempts against the exact platforms where each password was used.

Why 72,796 Credential Pairs Fuel Automated Attacks at Scale

A dataset of nearly 73,000 credential pairs is large enough to power sustained credential stuffing operations across dozens of major platforms. Automated tools like OpenBullet and SentryMBA can process thousands of login attempts per minute, cycling through proxy lists to avoid detection and rate limiting. The 72,796 records in Corps 12.01 provide ample fuel for these campaigns.

The threat compounds when password reuse enters the equation. Industry data indicates that roughly 65% of people use the same password for multiple accounts. This means each credential pair in this dataset potentially unlocks access to two, three, or more services beyond the one where it was originally captured. A single stolen password can open a chain of compromises across email, social media, financial, and workplace accounts.

Because the URLs in this dataset identify the original service for each credential, attackers can prioritize high-value targets first, then systematically expand to test reused credentials against other platforms, maximizing the return on each stolen password.


How Stealer Logs Are Assembled and Distributed

The Corps 12.01 dataset was assembled through infostealer malware deployed across multiple victim devices. The typical infection chain begins with a delivery mechanism such as a phishing email with a malicious attachment, a trojanized software download, or a drive-by download from a compromised website. Once executed, the infostealer runs silently in the background.

The malware targets specific data stores on the victim's machine: browser credential databases (Chrome, Firefox, Edge), email client configurations, FTP client saved sessions, and cryptocurrency wallet files. It compiles the extracted data into a standardized log format, typically organized by victim machine, and transmits the package to an attacker-controlled server.

These individual logs are then aggregated, filtered, and repackaged into themed collections like Corps 12.01 before being distributed through Telegram channels, dark web marketplaces, and private forums. The structured naming and numbering of this dataset indicate it was part of an ongoing series of distributions by the same actor or group.


Check If Your Credentials Were Harvested

If you were active online in early 2023, your credentials could be among the 72,796 records in the Corps 12.01 stealer log. HEROIC maintains a free breach scanner that indexes more than 400 billion records from known data breaches and stealer log distributions, including this dataset.

Enter your email address to check whether your credentials have been exposed. If they have, take immediate action: change your passwords on all potentially affected services, prioritize accounts with financial or sensitive data access, and activate multi-factor authentication to add a layer of defense that a stolen password alone cannot bypass.

Breach Breakdown

Domain Corps 12.01 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

72,796 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,580 scanned today
Breach Rank #N/A by affected users
Impact Score
3
sensitivity + scale + recency
Est. Financial Impact $526.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance