Our Analysts Found the ‘Segh’ Stealer Log With 643 Exposed Logins
In May 2024, HEROIC analysts discovered a stealer log labeled "segh" circulating in a Telegram channel, containing 643 records of email addresses, plaintext passwords, and browser URLs pulled from compromised devices. Why This Is Dangerous: Though small, this file still hands attackers 643 working sets of credentials. Because the passwords are stored in plaintext, there is no need for cracking or guesswork. Anyone who obtains the file can start using the logins right away. What Was Exposed: The data includes email addresses, plaintext passwords, and the specific URLs those passwords unlock, giving attackers a clear picture of which accounts each credential opens. Why This Matters: A small leak can still cause real damage if the affected person reuses passwords across multiple sites, which most people do. A single stolen password can lead to email compromise, account takeover, or fraudulent purchases if it unlocks a banking or shopping account elsewhere. How a Stealer Log Like This Works: Stealer logs are generated by malware that infects a device, often disguised as pirated software, a cracked game, or a fake update. Once active, it quietly copies saved browser passwords and session data, then sends everything to the attacker. The stolen records are then packaged into a file, in this case named "segh," and shared in Telegram channels where cybercriminals trade stolen data. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including stealer logs like this one. Run a free scan to see if your credentials were part of this leak.
Breach Breakdown
643 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds