The JohnDoeProject Dump Contains Exactly 28,132 Email and Password Pairs
HEROIC analysts found a stealer log file posted to a public Telegram channel on November 7, 2025, by an anonymous user operating under the name JohnDoeProject. The file contained exactly 28,132 records, each consisting of a real email address, a plaintext password, and the URL of the service where those credentials were aktively used. The scale and composition of this log indicate a sustained malware operation targeting real users across multiple platforms.
Why This Is Dangerous
Twenty-eight thousand plaintext passwords in one file is not a theoretical risk. Each one is ready to use without any additional work. Attackers can load the entire file into automated tools and begin testing login combinations across email providers, banking apps, and retail sites within hours of downloading it. The service URLs included in every record remove even the small hurdle of guessing which site each password belongs to.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Service URLs
Why This Matters
Credential stuffing is the most direct path from a leaked file to a compromised account. Criminals take the 28,132 email and password pairs from JohnDoeProject and run them through automated scripts that test each combination against dozens of popular websites simultaneously. Anyone who reuses the same password across accounts is especially vulnerable. A single match can mean a drained bank account, hijacked email, or stolen identity. The sheer number of records in this file means the campain behind it was broad and ongoing.
How Stealer Log Breaches Work
Infostealer malware is usually delivered through a deceptive download or a phishing email link. Once it runs on your computer, it operates invisibly, recording every password your browser autofills or that you type manually. It captures the website address alongside each password so the attacker has a complete picture of your online accounts. All of this data is transmitted back to the attacker and compiled into log files like JohnDoeProject. Those logs are then distributed through Telegram channels where hundreds or thousands of other criminals can access them instantly.
Check If You Are Affected
With 28,132 records in this single file, the odds are not insignificant. HEROIC's free dark web scanner searches your email address against more than 400 billion exposed records, including stealer logs like this one. It takes seconds and costs nothing. Run a free scan right now and know for certain whether your credentials are already circulating among criminals.
Breach Breakdown
28,132 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds