Mansory 20 Stealer Log Leak Exposes 1.9M Logins: Check Now
A Telegram Stealer Log Exposes Nearly Two Million Logins
On December 2, 2025, HEROIC analysts identified a stealer log file, labeled "Mansory 20," being shared by a user on Telegram. The file contained 1,963,358 individual records, each one pairing an email address with a plaintext password and the web address where that login was used. This is the typical output of information stealing malware: once it infects a device, it quietly copies every saved credential from the browser and packages it into a single file for the attacker to sell or trade.
Why This Is Dangerous
Because the passwords in this file are stored in plaintext, anyone who gets a copy can read and use them immediately, with no cracking or guessing required. Each record also includes the specific site the login belongs to, so an attacker does not have to guess where a stolen password might work. With almost two million entries in a single file, this log gives criminals a ready-made list of accounts to try opening, one by one or through automated scripts that run through the entire list in minutes.
What Was Exposed
- Email addresses
- Plaintext passwords
- Website login URLs tied to each credential
Why This Matters
A stolen email and password pair is the key to far more than one account. Since so many people reuse the same password across multiple sites, a single leaked login can open the door to email, banking, shopping, and social media accounts belonging to the same person. Attackers routinely run this kind of data through automated credential stuffing tools, testing each pair against dozens of popular services to see where else it works. When it succeeds, the result can be a full account takeover, unauthorized purchases, or identity theft carried out using information found inside the compromised accounts.
How Stealer Logs Work
A stealer log is the output of infostealer malware, a type of malicious software designed to run quietly on an infected computer and harvest anything of value it can find. Infostealers commonly pull saved usernames and passwords straight out of web browsers, along with autofill data, browser cookies, and sometimes cryptocurrency wallet files. Victims are usually infected through a malicious download, a cracked software installer, or a phishing link, often without ever noticing anything wrong. Once the malware finishes collecting data, it bundles everything into a log file like this one and sends it back to the attacker, who may use it directly or upload it to a Telegram channel or dark web forum where other criminals can buy or download it.
Check If You Are Affected
If you think an old password of yours might be sitting in a stealer log like this one, it is worth checking. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including stealer logs, credential dumps, and past data breaches, to tell you if your email address has turned up anywhere it shouldn't. Run a free scan, and if you find a match, change that password right away and turn on multi-factor authentication wherever it is offered.
Breach Breakdown
1,963,358 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds