Researchers Found 793 pps.duke.edu Logins in a Stealer Log
What HEROIC Analysts Found
In June 2026, HEROIC analysts observed a stealer log posted to a Telegram channel containing 793 records tied to pps.duke.edu, a Duke University domain. Watching the channel, analysts saw the log listed alongside dozens of others, each named for a different organization, each containing the same pattern: email addresses, plaintext passwords, and the login URLs those credentials open.
What Analysts Saw Happen Next
From the outside, nothing dramatic happens when a log like this is posted. There's no alert sent to the people affected, no company statement. The file simply sits there, available to anyone browsing the channel, until someone downloads it and starts testing the credentials against other services. That quiet, ordinary process is exactly how stealer log data ends up fueling far more visible attacks weeks or months later.
What Was Exposed
- Email addresses
- Plaintext (unencrypted) passwords
- Login URLs tied to each set of credentials
Why This Matters
Because the passwords in this log are stored as plain text, they are ready to use without any cracking. Anyone who reused their pps.duke.edu password on another account is exposed to credential stuffing, where automated tools test the same login across banking, email, and shopping sites. A compromised email address can also be used to reset passwords elsewhere, extending the reach of a single leaked credential.
How Analysts Trace Logs Back to Infostealer Malware
This data comes from infostealer malware, malicious software that infects a device, often through a fake download or cracked application, and quietly harvests saved browser passwords, autofill data, and active sessions. Analysts track these logs as they get merged with others into larger searchable collections, which is how a domain-specific leak like this one gets identified in the first place.
Check If You Are Affected
If you have a pps.duke.edu account, it's worth checking whether your credentials are part of this leak. HEROIC's free breach scanner checks your email against a database of more than 400 billion exposed records, including stealer logs like this one, so you can find out in seconds.
Breach Breakdown
793 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds