Someone Has Your Password: 41,594 GMX Credentials Leaked
A stealer log file labeled "GMX New Part 2" was shared on Telegram in January 2023, and HEROIC has confirmed it contains 41,594 stolen credential records. The dump specifically targets GMX email users, exposing their email addresses alongside plaintext passwords and the URLs of services where those credentials were captured by malware running on infected devices.
Your Password in Plaintext: Already Readable by Attackers
There is no protection layer on the passwords in this file. They are stored exactly as the victims typed them—in plain, unencrypted text. Anyone who downloads this dump from Telegram can immediately see every password, try every login, and compromise every account that still uses the exposed credential. The urgency to act cannot be overstated.
What Was Exposed
- Email Addresses – GMX accounts used for personal and professional communication worldwide
- Plaintext Passwords – Fully exposed login credentials with no encryption whatsoever
- URLs – The websites and services where the stolen credentials were originally entered
One Password, Many Compromised Accounts
The real danger of this leak extends far beyond GMX. If you have ever used your GMX email password on another service—an online store, a banking site, a streaming platform—attackers will find it. Credential stuffing bots systematically test every leaked email-password combination against thousands of popular websites, and it only takes one match to start an account takeover chain.
Stealer Logs: Malware That Watches You Type
The 41,594 records in this dump were not stolen from GMX servers. They were captured from individual users' devices by infostealer malware—trojans like Vidar, Aurora, or Raccoon Stealer. These programs infiltrate computers through malicious email attachments, fake software downloads, and compromised websites. Once active, they silently record saved browser passwords, intercept form submissions, and steal session cookies—all without the user ever noticing.
Check If Your Credentials Were Exposed
Do not assume you are safe. With 41,594 GMX-focused records in this dump alone, your email and password may already be circulating among cybercriminals. HEROIC's breach scanner searches over 400 billion compromised records to give you a definitive answer. Enter your email address now to find out if your credentials were exposed in the GMX New Part 2 leak or any other known data breach.
Breach Breakdown
41,594 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds