Plaintext Passwords Exposed: polimi.it Leak Hits 3,015 Accounts
What HEROIC Analysts Found
In June 2026, HEROIC analysts found a stealer log posted to Telegram containing 3,015 records tied to polimi.it, the domain used by Politecnico di Milano in Italy. The log included email addresses, plaintext passwords, and the login URLs those credentials open. This data was harvested from infected personal devices, not a breach of the university's own systems.
Zooming In: The Detail That Makes This Leak Usable
The single most important detail in this leak isn't the record count, it's the word "plaintext." Plaintext means the password sits in the log exactly as it was typed, with no scrambling or encryption to strip away. For an attacker, that one word is the difference between a file that requires hours of cracking and one that can be used the second it's downloaded.
What Was Exposed
- Email addresses
- Plaintext (unencrypted) passwords
- Login URLs tied to each set of credentials
Why This Matters
Because these passwords are plaintext, anyone who reused a polimi.it password on another account is exposed to credential stuffing, where the same login is tested automatically across banking, email, and shopping sites. A compromised university email can also be used to intercept password reset messages tied to other services, extending the risk beyond the original account.
How Stealer Logs Capture Plaintext Passwords
This leak traces back to infostealer malware, malicious software that infects a device, often through a fake download or cracked application, and quietly copies saved browser passwords exactly as the browser stores them, alongside autofill data and active sessions. The results are compiled into a log file and posted to Telegram, where they can be merged with other logs into larger searchable collections.
Check If You Are Affected
If you have a polimi.it account, it's worth checking whether your credentials appear in this leak. HEROIC's free breach scanner checks your email against a database of more than 400 billion exposed records, including stealer logs like this one, so you can find out in seconds.
Breach Breakdown
3,015 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds