Breach Intelligence Report 11 Apr 2026

Primo Stealer Logs: 1.76M Records Exposed

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs TG-Primo_Logs - ULP - Free 17_2T uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 1,761,415
Source Type Stealer log
Origin United States
Password Type plaintext

In February 2026, a massive credential theft operation compromised 1,761,415 Primo platform user records through stealer malware. The threat actor distributed the complete dataset on Telegram, marking one of the largest publicly distributed breaches of the year. The sheer volume makes this a coordinated, industrialized attack targeting ULP services at scale.

Why This Is Dangerous

At 1.76 million records, this breach crosses the threshold from targeted attack to mass market exploit. The dataset is large enough to populate entire criminal databases for credential stuffing operations, botnet infrastructure projects, and mass phishing campaigns. With plaintext passwords, attackers don't need computational resources to crack hashes—they can immediately attempt account takeover across financial systems, email services, and corporate networks where users reuse credentials.

What Was Exposed

  • 1,761,415 plaintext user passwords
  • Email addresses for mass phishing targeting
  • API endpoints revealing platform architecture
  • Internall service URLs and infrastructure identifiers
  • Session tokens enabling account impersonation

Why This Matters

Breaches of this magnitude have multiplicative impact. With nearly 1.8 million valid email-password pairs, threat actors can execute large-scale credential stuffing campaigns, targeting banking sites, email providers, and corporate systems simultaneously. The data becomes a commodity in underground markets, resold hundreds of times. Attackers use the plaintext passwords to establish persistent access into victim accounts, install remote access trojans, and maintain presence for long-term exploitation.

How Industrial-Scale Stealer Operations Work

Large stealer campaigns like this operate as systematic supply-chain attacks. Malware is distributed through trojanized software, software supply-chain compromises, or phishing campaigns. Once installed, the stealer operates silently for weeks or months, harvesting credentials, API keys, and sensitive files. The malware is designed to evade detection by running only during specific hours and staying dormant on weekends. When enough data is collected, exfiltration happens rapidly, and the stealer is distributed to resellers who monetize through public Telegram channels or dark web auctions.

Check If You're Affected

If you had a Primo account before February 2026, assume your credentials are comprommized and actively traded in underground markets. Change your password immediately on Primo and any other services using the same credentials. Enable two-factor authentification on critical accounts. Monitor your email for suspicious recovery requests or login alerts from financial institutions.

Breach Breakdown

Domain TG-Primo_Logs - ULP - Free 17_2T uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 11 Apr 2026
Check in 5 seconds

1,761,415 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,056 scanned today
Breach Rank #N/A by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $12.7M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance