The america.hm Exposed 1,520 Stolen Accounts on the Dark Web
HEROIC analysts identified this stealer log on 10-Jun-2026. The breach exposed 1,520 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as america.hm.
Why This Is Dangerous
This breach contains plaintext passwords, meaning they are stored in a fully readable format with no encryption. Anyone who obtains this data can immediately use these credentials to attempt to log in to accounts. Combined with matching email addresses and URLs that identify the target websites, attackers have everything they need to access the affected accounts directly.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
When login credentials are published on the dark web, cybercriminals use automated tools to try those username and password combinations across hundreds of websites. This technique, called credential stuffing, works especially well when people reuse passwords. A single breach like this can lead to account takeovers, identity theft, and financial fraud across multiple platforms.
How a Stealer Log Works
A stealer log is created by malware that secretly installs itself on a victim's computer, often through a malicious download or infected email. Once active, the malware records keystrokes, captures saved browser passwords, and collects login data from the device. This stolen information is packaged into a log file and sent to the attacker, who may sell or share it in places like private Telegram channels or dark web forums.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to see if your credentials appear here or elsewhere. Free, takes seconds.
Breach Breakdown
1,520 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds