63,905 Passwords From the JohnDoeProject Dump Just Surfaced on Telegram
In August 2025, security analysts discovered a stealer log file uploaded to a public Telegram channel by an anonymous user. The file, tied to a dump now known as the JohnDoeProject leak, contained 63,905 records pulled directly from compromised devices. Each record included an email address, a plaintext password, and a URL pointing to the site or API the victim had accessed. The data was not encrypted or scrambled in any way, meaning anyone who downloaded the file had instant, ready-to-use login credentials.
Why This Is Dangerous
When attackers get their hands on plaintext passwords paired with email addresses, they do not sit idle. They load those credentials into automated tools and start testing them against Gmail, Outlook, banking apps, PayPal, and dozens of other platforms within hours. If you used the same password somewhere else, that account is now at risk. The URLs in this dump also tell attackers exactly which services the victims were logged into, making it trivially easy to prioritise which accounts to target first. API host URLs in the data are especially worrying because they can give attackers programatic access to back-end systems, not just a single user account.
What Was Exposed in the JohnDoeProject Dump
- Email addresses
- Plaintext passwords (completely unencrypted)
- URLs, including API host endpoints
Why This Matters
Most people reuse passwords. That is the uncomfortable truth that makes stealer log dumps so devestating. A password grabbed from one compromised device can unlock a bank account, a work email, a health portal, or a social media profile. Once attackers get into one account, they often find enough information to answer security questions and reset passwords on others. Identity theft, fraudulant purchases, and account lockouts tend to follow quickly. Even if you were not directly infected by the malware, if your credentials appeared in this log you are at real risk.
How Stealer Log Breaches Work
A stealer log breach starts when malware quietly installs itself on a victim's computer, often through a fake software download, a phishing email, or a malicious ad. Once running, the malware watches for passwords being typed or stored in browsers and apps, then copies them along with the associated URLs and sends everything to a server controlled by the attacker. The attacker then bundles all of this stolen data into a single log file. These log files are frequently posted to Telegram channels or sold on underground forums where other criminals can download them and immediately start using the credentials. The whole process from infection to public leak can happen in less than 24 hours.
Check If You Are Affected
HEROIC's free scanner searches across more than 400 billion compromised records, including dumps like this one, to tell you instantly whether your email address has been exposed. It takes less than a minute and requires no account signup. If your credentials appear in the JohnDoeProject leak or any other breach in our database, you will know right away so you can change your passwords before an attacker uses them.
Breach Breakdown
63,905 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds