Inside Epic Games Stealer Logs: 142 Passwords Harvested
HEROIC's threat intelligence team identified a stealer log file titled Epic Games Inboxed Hits circulating on Telegram. The file contains 142 records of compromised credentials, each consisting of an email address, a plaintext password, and the URL where the login was captured. The data was extracted from devices infected with infostealer malware.
Plaintext Passwords: Zero Steps Between Theft and Access
Every password in this dump is stored in plaintext, which means attackers can use them without any additional processing. There is no hashing to reverse, no encryption to break. The moment someone accesses this stealer log, they have working login credentials that can be tested instantly against Epic Games accounts and beyond.
What Was Exposed
- Email addresses associated with Epic Games accounts
- Plaintext passwords captured during login sessions
- URLs of Epic Games and related service login pages
Credential Stuffing Puts All Your Accounts at Risk
Gamers often use the same email and password for multiple gaming platforms, streaming services, and social media. Attackers exploit this by running credential stuffing attacks, automatically testing each stolen pair against hundreds of sites. A compromised Epic Games login can quickly become a compromised Steam, PlayStation, or banking account.
How Stealer Logs Capture Gaming Credentials
Infostealer malware often spreads through fake game mods, cracked software downloads, and phishing links shared in gaming communities. Once installed, the malware silently records every password saved in the victim's browser, captures active session cookies, and compiles the data into stealer logs that are then traded or posted on Telegram.
Check If Your Credentials Were Exposed
If you have an Epic Games account, your credentials may be in this leak or others like it. Run your email through the HEROIC breach scanner to search across more than 400 billion compromised records. Discovering your exposure early allows you to change passwords and enable two-factor authentication before attackers strike.
Breach Breakdown
142 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds