Search Your Email: The JohnDoeProject Dump Exposed 49,598 Accounts
In July 2025, security analysts discovered a stealer log file that had been posted to a public Telegram channel by an anonymous user. The file, catalogued as the JohnDoeProject dump, contained 49,598 records pulled directly from compromised devices. Every entry included an email address, a plaintext password, and a URL pointing to the site or API host the victim had accessed. The passwords were not encrypted or protected in any way. Anyone who downloaded the file could begin using those credentials immediately, with no technical skill required.
Why This Is Dangerous
A dump of 49,598 ready-to-use email and password pairs is a serious resource for attackers. Credential stuffing tools can automatically test these combinations against Gmail, Outlook, banking sites, PayPal, Spotify, and hundreds of workplace platforms simultaneosly. Because the log also includes the URLs the victims visited, attackers know exactly which services to prioritise. API host URLs are especially concerning because they can provide programatic access to corporate back-end systems, not just a single personal account. A breach like this can affect individuals and organisations alike, even when only a single device was originally compromised.
What Was Exposed in the JohnDoeProject Dump
- Email addresses
- Plaintext passwords (completely unencrypted)
- URLs, including API host endpoints
Why This Matters
The danger of a stealer log is multiplied by password reuse. If the same password was used on more than one site, every one of those accounts is now at risk. Attackers use credential stuffing to test stolen logins across dozens of platforms, and they are remarkably succesfull at it because so many people reuse passwords. Account takeover can lead to fraudulant purchases, drained bank accounts, stolen identities, and locked-out profiles that take weeks to recover. Even people with strong security habits can be affected if their credentials appear in a dump from a single compromised device.
How Stealer Log Breaches Work
Infostealer malware is the engine behind leaks like this one. The malware typically arrives on a victim's device through a fake software download, a phishing email, or a malicious browser extension. Once running, it silently collects passwords saved in browsers, captures login details as they are typed, and records which websites the device accessed. All of this data gets bundled into a log file and sent to the attacker's server without the victim ever knowing. The attacker then posts or sells the log on Telegram and dark web forums, where other criminals download it to run their own attacks. The whole process from infection to weaponised dump is remarkably fast.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion compromised records, including this JohnDoeProject dump and thousands of other leaks. Enter your email address and find out in seconds whether your credentials have been exposed. No account needed, no payment required. If your email appears in this leak, change the associated password right away and check whether you used the same password anywhere else.
Breach Breakdown
49,598 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds