1.7 Million Passwords Exposed in the Mansory 5 Stealer Leak
In January 2026, a stealer log file labeled "Mansory 5" surfaced on Telegram, exposing 1,747,520 records pulled from malware-infected devices. The trove includes email addresses, plaintext passwords, and the URLs those credentials unlock, giving anyone who downloads it a ready-made list of working logins.
The name "Mansory 5" is simply the label a threat actor gave this batch of stolen data. It is not a breach of a company called Mansory. Stealer logs like this one are compiled from information-stealing malware that infects individual computers and phones, not from a single company's servers being hacked.
Why This Is Dangerous
What makes this leak especially risky is that the passwords were captured in plaintext. There is no scrambled hash to crack and no encryption to break through. Anyone who gets a copy of this file can read the passwords exactly as the victims typed them, then pair each one with its matching email address and the site it unlocks.
Because the URLs are included alongside the credentials, attackers do not have to guess where a password works. The log effectively hands them a map showing which login goes with which account, making it far easier to break in on the first try.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to the affected login accounts
Why This Matters
Over 1.7 million exposed logins is a large enough pool that criminals can automate the damage. Stolen email and password pairs get fed into credential stuffing tools that test the same combination across banking sites, email providers, and shopping accounts in bulk. Since so many people reuse passwords, one exposed login can lead to several accounts being taken over.
From there the path to harm is short. Account takeover lets an attacker lock the real owner out, identity theft becomes possible once enough personal details are pieced together, and financial fraud follows quickly if a banking or payment login is among the 1,747,520 records.
How Stealer Log Leaks Work
Stealer logs come from malware that quietly runs on an infected device and copies whatever is saved in the browser: stored passwords, autofill data, and session details. That stolen information is bundled into a file and sold or, as in this case, uploaded directly to a Telegram channel where anyone can grab it for free.
Because the malware harvests credentials directly from the victim's own device, the leak has nothing to do with whether any particular website was secure. It only depends on whether the victim's computer or phone was infected at the time.
Check If You Are Affected
With 1,747,520 records in this single log, the odds that your email address is included are real. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including stealer logs like Mansory 5, so you can find out in seconds whether your information was exposed and take action before someone else uses it against you.
Breach Breakdown
1,747,520 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds