Researchers Link the Second Base Dump to Nearly 10,000 Stolen Logins
HEROIC Analysts Trace the Second Base Stealer Log to Nearly 10,000 Exposed Logins
HEROIC analysts identified a stealer log labeled 30-June Second Base, uploaded to a Telegram channel on 30 June 2026. The file contained 9,974 records, each pairing an email address with a plaintext password and the URL of the site where that login was captured. Almost ten thousand people had their working credentials pulled directly from an infected device and dropped into a channel where anyone can download them for free.
Why This Is Dangerous
Because this data came from malware running on victims' own computers rather than an old hacked database, the credentials reflect logins that were active and in use recently. There is no need for an attacker to crack a password hash or guess anything. The email, the password, and the exact site it belongs to are all sitting in the same file, ready to use.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the sites where the credentials were used
Why This Matters
With close to 10,000 credential pairs in one file, an attacker has a ready-made list to run through automated tools that test the same email and password combination across dozens of other websites, a tactic known as credential stuffing. Anyone in this log who reused a password on their email, bank, or social media account is at risk of having those accounts taken over as well. Once an attacker is inside one account, identity theft and financial fraud often follow quickly.
How Stealer Logs Work
A stealer log is the output of information-stealing malware, which typically infects a device through a pirated download, a fake software crack, or a malicious attachment. Once installed, it silently harvests saved passwords, autofill data, and active browser sessions, then packages everything into a text file. Files like this one, sized in the thousands of records, usually come from multiple infected machines pooled together and traded on Telegram channels or dark web forums. Because the data reflects real, recent activity on the victims' own devices, it tends to be far more usable to criminals than credentials pulled from years-old breach dumps.
Check If You Are Affected
If you think you might be one of the nearly 10,000 people in this leak, or you simply want peace of mind, HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including stealer logs like this one. You will find out immediately whether your information has been exposed. Run a free scan now to check your status.
Breach Breakdown
9,974 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds