Numpass Stealer Log Leaks 476,945 U.S. Logins and Passwords
Numpass Stealer Log Exposes Nearly 477,000 U.S. Logins
On December 16, 2022, HEROIC analysts identified a stealer log file, labeled "numpass," being distributed by a user on Telegram. The file contained 476,945 records, each pairing an email address with a plaintext password and the web address the login was used on. HEROIC's records list the accounts in this log as based in the United States, making it a large collection concentrated on one country's users.
Why This Is Dangerous
Because the passwords in this file are stored in plaintext, they can be used immediately by anyone who obtains the log, with no cracking or guesswork needed. Each entry also lists the exact site the credential belongs to, letting an attacker quickly sort victims by the type of account, whether that is email, banking, or retail. With nearly half a million records concentrated on U.S. accounts, this log gives criminals a large, geographically focused target list.
What Was Exposed
- Email addresses
- Plaintext passwords
- Website login URLs tied to each credential
Why This Matters
A leaked login rarely stays limited to a single account. Since so many people reuse the same password across multiple services, one exposed credential can open the door to email, banking, or shopping accounts belonging to the same person. Attackers commonly run large logs like this through automated credential stuffing tools, testing each pair against popular U.S. based services in search of account takeover, financial fraud, or a path toward identity theft.
How Stealer Logs Work
This file was produced by infostealer malware, which infects a device through a malicious download, cracked software, or a phishing link, then quietly copies saved logins out of the victim's browser. The malware bundles everything it finds into a log file and sends it back to whoever controls it. From there, the data may be sold or shared through Telegram channels or dark web forums, where other criminals can access it and put it to use.
Check If You Are Affected
With nearly 477,000 records exposed, it is worth checking whether your information is part of this list. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one, to show you if your email address has appeared anywhere it shouldn't. Run a free scan, and if you find a match, change that password right away and turn on multi-factor authentication wherever it is available.
Breach Breakdown
476,945 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds