The Moon_Bases Leak Has More Records Than the Population of San Jose
HEROIC analysts flagged a large stealer log dump, internally tracked as Moon_Bases, that a Telegram user uploaded on June 29, 2025. The file contained 1,180,446 records, more people than currently live in San Jose, California, all pulled from malware-infected devices. Each record includes an email address, a plaintext password, and the URL the credentials were used on, giving criminals a ready-made map of exactly which accounts to target.
Why the Moon_Bases Leak Is Dangerous
A dump of this size is not just a numbers game. Every one of the 1,180,446 entries pairs a working login with the exact site it unlocks, which strips away the guesswork attackers usually have to do. Because the passwords are stored in plaintext, anyone who downloads the Moon_Bases file can immediately try logging into email inboxes, shopping accounts, and other services without cracking a single hash. At this scale, even a small success rate translates into tens of thousands of compromised accounts.
What Was Exposed in the Moon_Bases Dump
- Email addresses linked to real accounts
- Plaintext passwords with no encryption to slow attackers down
- URLs identifying the exact site or service each login belongs to
Why This Matters for the 1.18 Million People Affected
When over a million email and password pairs go public, the fallout rarely stays contained to one site. Attackers automate credential stuffing attacks, feeding these exact combinations into login pages across banking, retail, and social media platforms to see which ones still work. Anyone who reused a password from this leak on another account has effectively handed over a spare key. From there, it is a short step to identity theft, fraudulent purchases, and hijacked accounts that are hard to recover.
How a Stealer Log Like Moon_Bases Gets Built
Stealer malware infects a device through phishing links, cracked software, or malicious downloads, then quietly harvests everything saved in the browser: usernames, passwords, autofill fields, and session data. That information is compiled into a structured log file and either sold on dark web marketplaces or, as happened here, uploaded directly to a Telegram channel for anyone to grab. The sheer volume in the Moon_Bases file, over 1.1 million lines, suggests it was aggregated from many infected machines rather then a single victim, which is common practice among stealer operators looking to build a reputation before selling access to bigger buyers.
Check If You Are Affected by the Moon_Bases Leak
With 1,180,446 records now circulating, checking your exposure only takes a minute. HEROIC's free breach scanner searches your email against a database of more than 400 billion leaked records, including this Moon_Bases stealer log, so you know right away if you need to act. If you find a match, change that password immediately, avoid reusing it anywhere else, and turn on two-factor authentication. Scan now before someone else uses your credentials first.
Breach Breakdown
1,180,446 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds