The SEGA 18122 Dump: 1,159 Stolen Login Credentials Hit Telegram in December 2022
HEROIC analysts flagged the SEGA 18122 stealer log after a Telegram user uploaded it on December 18, 2022. The file contained 1,159 records taken from compromised endpoints by infostealer malware. While smaller in volume than some other stealer log batches, each record is just as dangerous, pairing a real email address with a plaintext password and a URL identifying the service where those credentials were used. The SEGA 18122 batch is part of the same campaign series as other SEGA-labeled logs released around the same time, indicating a coordinated credential harvesting operation. Every record in this file was accessible to anyone who found it on Telegram.
Why Even 1,159 Leaked Passwords from SEGA 18122 Are a Serious Problem
Small does not mean safe when it comes to stealer logs. A file with 1,159 plaintext credentials can still compromise 1,159 people, and each one of those people may have reused that password on multiple services. Attackers do not need a massive dataset to cause serious harm. Automated credential stuffing tools can cycle through a file this size against hundreds of target websites in under an hour. The API host URLs are particularly valuable in smaller logs like this one because they often point to specialized services, developer tools, or corporate systems rather than everyday consumer apps. That specificity can make these records more valuable to a targeted attacker rather than less.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API hosts and accessed services)
Why Older Stealer Logs Still Fuel Account Takeover Today
A leak from December 2022 is not ancient history when it comes to credential security. Many people have not changed their passwords since then, and seperate services often share the same login details. Attackers who acquire this log can still use it today to attempt account takeover across banking, email, and business platforms. Identity theft can follow once an attacker is inside an email account and begins harvesting personal information. Financial fraud becomes a real risk when credentials tied to payment services or banking apps are still active. Even credentials that no longer work on the original service may unlock other accounts where the same password was reused.
How Stealer Log Campaigns Like SEGA Target Everyday Users
Infostealer malware is not a sophisticated hacking operation from the victim's perspective. It looks like a legitimate software download, a cracked game, or an email attachment that seems harmless. Once it runs on a device, it searches for saved browser passwords, captures form inputs during login, and reads credential files stored by applications. It also records the URLs associated with each credential so the attacker knows which service was accessed. The harvested data is packaged into a clean log file and sent to the campaign operator, who then uploads it in batches to Telegram under names like SEGA 18122. The victim has no idea this has occured. The operators of these campaigns often release multiple batches over days or weeks, which explains why there are several SEGA-labeled logs from the same date range.
Check If You Are in the SEGA 18122 Leak
If you had active accounts in December 2022 and have not updated your passwords since, you could beleive your credentials are safe when they are not. HEROIC's free breach scanner checks your email address against a database of over 400 billion leaked records, including stealer logs like this one, dark web credential dumps, and major breaches going back years. It is completely free and takes only seconds. Visit heroic.com to run a scan and find out whether your data has been exposed in this or any other known breach.
Breach Breakdown
1,159 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds