U.S. Stealer Log Exposes 13,894 Emails From anon.penet.fi Users
A Stealer Log Tied to anon.penet.fi Surfaces on Telegram
In June 2026, HEROIC analysts tracking dark web and Telegram-based data leaks identified a stealer log file uploaded by an anonymous Telegram user. The file, dated 10 June 2026, contained 13,894 records tied to anon.penet.fi, including email addresses, plaintext passwords, and the URLs where those credentials were entered.
Why This Is Dangerous
Unlike a typical hacked database, a stealer log is a direct capture of what was sitting on someone's infected computer at the moment malware ran. That means the passwords in this file are not hashed or scrambled in any way, they are the exact plaintext password the victim typed in, paired with the exact web address it was used on. An attacker doesn't need to guess or crack anything. They can copy the email, password, and URL directly into a browser and log in as the victim.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the sites where the credentials were used
Why This Matters
Because these are real, working plaintext passwords tied to real URLs, this data is immediately useful for credential stuffing attacks, where criminals try the same email and password combination across banking, email, and shopping sites. If any of the 13,894 people in this log reused a password elsewhere, they are at risk of account takeover, identity theft, and financial fraud, all without the attacker doing any additional hacking.
How This Stealer Log Was Built
Stealer logs like this one come from info-stealing malware, malicious software that infects a device (often through cracked software, fake downloads, or phishing attachments) and quietly harvests everything saved in a victim's browser: usernames, passwords, autofill data, and browsing history. The malware then bundles this information into a log file and sends it back to whoever controls it. From there, logs are often shared, sold, or uploaded to Telegram channels, exactly as happened with this anon.penet.fi-linked file, where anyone can pick it up and use it.
Check If You Are Affected
You don't have to wonder whether your information is sitting in a stealer log like this one. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including stealer logs, combolists, and breached databases from across the dark web. Run a free scan now to see if your credentials have been exposed, and change any reused passwords immediately if they have.
Breach Breakdown
13,894 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds