Telegram User Leaks Mansory 5 Stealer Log, 2.8M Credentials
In March 2026, a Telegram user uploaded a stealer log dataset labeled "Mansory 5" to a public channel. The upload contains 2,844,838 records pulled from malware-infected devices, including email addresses, plaintext passwords, and the URLs of the accounts those passwords open. HEROIC's threat intelligence team has verified the data as authentic and added it to our breach database, which now tracks details from more than 400 billion exposed records worldwide.
Who Actually Leaked the Mansory 5 Data
This wasn't a company that got hacked. A single Telegram user compiled and posted the Mansory 5 file, and the credentials inside it were never stolen from one central source. Instead, they were harvested one device at a time by info-stealing malware running quietly in the background on victims' own computers, collecting saved passwords, cookies, and autofill entries before the operator packaged everything together and shared it. Because the passwords in this file are plaintext, anyone who downloads it can read every login instantly, without cracking or decrypting anything.
What the Telegram Upload Contains
- Email addresses
- Plaintext passwords
- URLs showing exactly which site or service each password unlocks
The inclusion of matching URLs means whoever grabs this file doesn't need to guess where an email and password combination might work. They can go straight to the correct login page and try it immediately.
Why This Matters for You
If your credentials are part of the 2.8 million records in Mansory 5, you're at risk of credential stuffing, where attackers automatically test the same email and password across many other sites. A single reused password can lead to account takeover, and from there to identity theft or financial fraud. Because the malware behind this leak sat on an infected device long enough to gather this much data, other personal details on that machine may also have been captured.
How a Telegram User Gets Access to a Stealer Log This Size
Info-stealing malware spreads through malicious downloads, cracked software installers, phishing attachments, and fake update prompts. Once it infects a device, it silently pulls every saved password, cookie, and autofill field it can find and sends the results back to whoever controls it. Telegram has become a common marketplace for these files, with users like the one behind Mansory 5 buying, trading, or freely posting stealer logs to channels with little oversight.
Check If You Are Affected
Don't wait to find out the hard way. HEROIC's free breach scanner checks your email address against more than 400 billion leaked and stolen records, including stealer logs like Mansory 5. Run a free scan today, and if you find a match, change the affected passwords right away and enable multi-factor authentication wherever it's available.
Breach Breakdown
2,844,838 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds