Researchers Link the 272210_BR Telegram Stealer Log to 79 Stolen Credentials from Brazilian Endpoints
HEROIC analysts identified and verified a stealer log, tracked as 272210_BR_187.123.2.82_08-06-23, distributed on Telegram in June 2023. The file contained 79 records sourced from Brazilian endpoints, exposing plaintext passwords, email addresses, and URLs. At 79 records, this is one of the larger files in this batch of Telegram-distributed stealer logs, giving attackers a substantial set of credentials to exploit.
Why the 272210_BR Stealer Log Is Dangerous
Seventy-nine plaintext credential pairs give attackers a ready-to-use attack kit. Each record contains an email address, its matching password in readable form, and the URL of the service that was targeted. Attackers can run all 79 pairs through automated credential stuffing tools in a matter of minutes, testing them across banking sites, corporate portals, email providers, and e-commerce platforms. The hit rate on such attacks is consistently high because password reuse is widespread.
What Was Exposed in 272210_BR
- Email Addresses
- Plaintext Passwords
- URLs (endpoint and API host references)
Why This Matters
Files with 79 records are regularly absorbed into large combolists that aggregate thousands of credentials from multiple stealer logs. Once bundled into a combolist, these credentials are tested far more broadly and persist in the criminal ecosystem for years. Each victim faces ongoing risk of account takeover, financial fraud, and identity theft, not just from the original file, but from every combolist that later includes their credentials. The 272210_BR log represents an active, ongoing threat to the people whose data it contains.
How Stealer Log Breaches Like 272210_BR Work
Security researchers tracking infostealer activity observe these files being posted to Telegram channels daily. Each log originates from one or more devices infected with malware that silently collects saved credentials and sends them to an attacker-controlled server. The attacker packages the collected data into a numbered log file and publishes it to Telegram, where it is downloaded and reused. The 272210_BR file follows this exact pattern, with the BR country code indicating the targeted devices were located in Brazil.
Check If You Are Affected
HEROIC's free breach scanner covers more than 400 billion exposed records across thousands of verified stealer logs and data breaches. Run a free scan at HEROIC to find out whether your email address or password appeared in the 272210_BR log or any other breach in the database.
Breach Breakdown
79 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds