Over 1,000 Corporate Logins Leaked in Maldives Stealer Sample
In February 2026, a Telegram user uploaded a stealer log file labeled as a "test sample" tied to corporate email accounts connected to the Maldives. The file contained 1,041 records, including email addresses, plaintext passwords, and the URLs of the accounts those credentials unlock, all pulled straight from malware-infected devices.
Why a "Test Sample" Leak Still Matters
Sellers of stolen credential data often post a small "test sample" publicly to prove that a larger batch is real and working before offering the full set for sale. Even at 1,041 records, this file represents live, functional logins tied to corporate email accounts. A small sample is not a small risk; every credential in it can be used the moment it is posted, and it often signals a much larger dataset changing hands privately.
What Was Exposed
- Corporate email addresses
- Plaintext passwords
- URLs of the accounts and services those credentials access
Why This Matters
Because the passwords in this sample were leaked in plaintext, no encryption stands between an attacker and the account behind each email. Corporate credentials are a particularly valuable target for credential stuffing attacks, where automated tools try leaked logins across dozens of other sites and services. A single reused password can open the door to account takeover, internal systems, or financial fraud against the business or individual behind the account.
How Stealer Log Test Samples Reach Telegram
Infostealer malware infects a device, often through a fake download, cracked software, or a malicious attachment, and silently harvests every saved password, autofill entry, and login session from the browser. Sellers then split that stolen data into a small "test sample," posted publicly on Telegram to prove the data works, while the rest of the batch is sold privately to other criminals. This file is explicitly labeled a "test sample," which fits that pattern: a proof-of-concept slice offered ahead of a larger stolen dataset.
Check If You Are Affected
If you use a corporate email account connected to the Maldives, or you suspect your login details may appear in this file, do not wait to find out the hard way. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including stealer log samples like this one, and tells you instantly if you have been exposed. Run a free scan today and secure your accounts before this data is put to use.
Breach Breakdown
1,041 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds