The 500K Leak Exposed 496,182 Accounts on the Dark Web
HEROIC analysts tracked a large stealer log dataset shared on Telegram in December 2022 that exposed 496,182 records. The file, labeled 500K, contains email addresses, plaintext passwords, and URLs gathered from infected devices by information-stealing malware. Nearly half a million records in a single Telegram-distributed dataset places this among the higher-volume stealer log releases tracked by HEROIC from that period.
What Half a Million Exposed Logins Mean for Account Security
At nearly 500,000 records, this dataset provides attackers with a substantial pool of ready-to-use credentials. Email addresses paired with plaintext passwords and the URLs they were captured from give threat actors both the login details and the context of which platforms each victim uses. This combination is optimized for credential stuffing operations targeting the highest-value accounts those victims hold.
What the 500K Leak Exposed
- Email Addresses
- Plaintext Passwords
- URLs (login endpoints from which credentials were harvested)
Nearly 500,000 Accounts at Risk: The Scale of Credential Stuffing Attacks
Automated credential stuffing tools can test hundreds of thousands of email and password combinations per hour across multiple platforms simultaneously. With 496,182 records, even a small success rate translates to tens of thousands of successfully compromised accounts. Victims whose credentials appear here face account takeover risk across any platform where they used the same password, including banking, email, and social media services.
How Stealer Log Breaches Work
Stealer logs are created by malware silently installed on victims' computers that records login credentials from browsers, password managers, and web forms. The credentials from thousands of infected devices are pooled and packaged into bulk files like this 500K dataset and then distributed through Telegram channels frequented by cybercriminals. Users often have no idea their device was infected or that their credentials are circulating in these collections.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records, including this 500K dataset and thousands of similar stealer log files. Enter your email to find out immediately whether your credentials are included, and consider using a password manager to create unique passwords for each account to reduce your exposure from future breaches.
Breach Breakdown
496,182 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds