Someone Has Your .it Domain Password: 144,613 Credentials Leaked
In April 2023, HEROIC analysts discovered a stealer log collection specifically targeting Italian .it domains that had been uploaded to a public Telegram channel. The file, labeled "185K Italian It Domain," contained 144,613 records of stolen credentials, each including an email address, a plaintext password, and the URL of the website where the login was captured. This geographically focused dataset represents a concentrated threat against users of Italian online services.
Why Plaintext Passwords Put Victims at Immediate Risk
Every password in the Italian .it Domain dump was stored in plaintext, meaning there is no cryptographic barrier standing between an attacker and a working login. Unlike hashed passwords that require time-consuming cracking attempts, these credentials can be copied and pasted directly into login pages the moment an attacker downloads the file.
This immediacy is what makes plaintext stealer logs so dangerous. Within hours of a dump appearing on Telegram, automated tools can test thousands of credential pairs against popular services, including email providers, banking platforms, and government portals commonly used by Italian residents.
What Was Exposed in the Italian .it Domain Dump
- Email Addresses — Email accounts associated with Italian .it domains, providing attackers with both a login identifier and a communication channel they can exploit for phishing or social engineering.
- Plaintext Passwords — Passwords stored in their original, readable form, requiring no decryption or brute-force effort to use against victim accounts.
- URLs — The exact web addresses where credentials were entered, mapping out which Italian services and platforms each victim relied on and enabling precisely targeted account takeover attempts.
Why a Regionally Targeted Leak Amplifies the Danger
When stolen credentials are concentrated around a specific country or domain, the risk of successful credential stuffing increases dramatically. Attackers know that users within the .it ecosystem are likely to share common services — Italian banks, government portals, telecom providers, and regional e-commerce sites. This allows them to build highly targeted attack lists rather than spraying credentials across random platforms.
Password reuse compounds the problem. Research consistently shows that most people use the same password across multiple services. A single compromised .it email and password pair could unlock not just the original account but also banking apps, social media profiles, and workplace systems tied to the same individual.
For the 144,613 people whose records appear in this dump, the combination of a known email, a working password, and a map of their online activity creates an unusually complete attacker profile.
How Stealer Logs Target Specific Regions and Domains
Infostealer malware — variants like RedLine, Raccoon, and Vidar — operates by infecting individual devices through malicious downloads, phishing emails, or compromised software. Once installed, the malware silently extracts saved passwords from browsers, captures keystrokes, and harvests autofill data, bundling everything into structured log files.
These raw logs are then sorted and filtered by threat actors or data brokers. A collection labeled by country or domain type, like this Italian .it dump, indicates that someone curated the data specifically for buyers interested in targeting Italian users. This curation makes the dataset more actionable and more valuable on underground markets.
The Telegram distribution model allows these curated collections to spread rapidly to a wide audience of attackers, many of whom specialize in exploiting regional services where security practices may vary and where victims may be slower to detect unauthorized access.
Check If Your Credentials Appear in This Leak
If you use an Italian .it email address or regularly log into Italian websites, your credentials could be among the 144,613 records exposed in this stealer log. HEROIC provides a free breach scanner that searches more than 400 billion compromised records to determine whether your email has been exposed.
Enter your email address to check your exposure. If your credentials are found in this or any other breach, take immediate action: change your passwords on all affected accounts, activate multi-factor authentication, and use a password manager to ensure every account has a unique, strong password going forward.
Breach Breakdown
144,613 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds