The 100k Streaming Base Data Quietly Appeared on the Dark Web
HEROIC analysts discovered a stealer log file shared on Telegram in January 2023, exposing 99,963 records from a collection described as a 100k streaming base. The breach includes email addresses, plaintext passwords, and URLs harvested from infected devices.
Streaming Credentials Are High-Value Targets for Resale
Attackers prize streaming service logins because they are immediately resalable. Stolen credentials for platforms like Netflix, Disney+, or Spotify are bundled and sold within hours of a breach surfacing on Telegram.
What the 100k Streaming Base Leak Exposed
- Email Addresses
- Plaintext Passwords
- URLs (endpoint context)
Account Sharing Makes Streaming Breaches Multiply
Many streaming users share one account across multiple people. When attackers gain access, they quietly change account credentials, locking out the original owner. The same email and password pairs are then tested against email providers, banking apps, and social media accounts.
How Stealer Log Breaches Work
Stealer logs are produced by malware silently installed on victims' computers. The malware captures usernames, passwords, and browser session data before sending it to criminals, who then package and sell the data on Telegram channels and dark web markets.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion+ leaked records to tell you if your email was part of this or any other stealer log dump. Check your exposure now at no cost.
Breach Breakdown
99,963 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds