Stealer Log Breach: 10,905 USA and EU Corporate Emails Leaked
In late June 2025, a file titled 10K USA EU Corp Mail Access By Kommander0 23.06 uploaded by a Telegram User appeared on Telegram, containing 10,905 records of corporate email access spanning the United States and Europe.
Why This Is Dangerous
Unlike a typical consumer leak, this one is aimed squarely at business inboxes. Corporate email accounts often connect to internal systems, shared drives, payroll platforms and client communications, so a single compromised login can open the door to an entire companys network, not just one person's messages.
What Was Exposed
- 10,905 total records
- Email Addresses
- Plaintext Password
- URLs tied to each corporate login
Why This Matters
Business email compromise is one of the costliest categories of cybercrime out there, and it usually starts exactly like this, with a stolen set of working credentials. Employees loosing control of their inbox can mean fraudulent wire transfers, leaked client data, or a foothold attackers use to move deeper into a company's systems.
How Stealer Logs Work
Stealer malware doesn't care whether a device is personal or work issued, it grabs whatever login data it can find. In this case, that included corporate mail platforms across the USA and EU, all bundled into one file and labeled by the actor who assembled it before sharing it on Telegram.
Check If You Are Affected
If you or your business use corporate email in the USA or EU, it's worth checking this leak specifically. HEROIC's free breach scanner searches over 400 billion leaked records, so you and your team can confirm exposure and reset credentials before attackers make a move.
Breach Breakdown
10,905 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds