Primo Stealer Logs: 1.76M Records Exposed
In February 2026, a massive credential theft operation compromised 1,761,415 Primo platform user records through stealer malware. The threat actor distributed the complete dataset on Telegram, marking one of the largest publicly distributed breaches of the year. The sheer volume makes this a coordinated, industrialized attack targeting ULP services at scale.
Why This Is Dangerous
At 1.76 million records, this breach crosses the threshold from targeted attack to mass market exploit. The dataset is large enough to populate entire criminal databases for credential stuffing operations, botnet infrastructure projects, and mass phishing campaigns. With plaintext passwords, attackers don't need computational resources to crack hashes—they can immediately attempt account takeover across financial systems, email services, and corporate networks where users reuse credentials.
What Was Exposed
- 1,761,415 plaintext user passwords
- Email addresses for mass phishing targeting
- API endpoints revealing platform architecture
- Internall service URLs and infrastructure identifiers
- Session tokens enabling account impersonation
Why This Matters
Breaches of this magnitude have multiplicative impact. With nearly 1.8 million valid email-password pairs, threat actors can execute large-scale credential stuffing campaigns, targeting banking sites, email providers, and corporate systems simultaneously. The data becomes a commodity in underground markets, resold hundreds of times. Attackers use the plaintext passwords to establish persistent access into victim accounts, install remote access trojans, and maintain presence for long-term exploitation.
How Industrial-Scale Stealer Operations Work
Large stealer campaigns like this operate as systematic supply-chain attacks. Malware is distributed through trojanized software, software supply-chain compromises, or phishing campaigns. Once installed, the stealer operates silently for weeks or months, harvesting credentials, API keys, and sensitive files. The malware is designed to evade detection by running only during specific hours and staying dormant on weekends. When enough data is collected, exfiltration happens rapidly, and the stealer is distributed to resellers who monetize through public Telegram channels or dark web auctions.
Check If You're Affected
If you had a Primo account before February 2026, assume your credentials are comprommized and actively traded in underground markets. Change your password immediately on Primo and any other services using the same credentials. Enable two-factor authentification on critical accounts. Monitor your email for suspicious recovery requests or login alerts from financial institutions.
Breach Breakdown
1,761,415 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds