The TXTLOG_ALIEN – 703 Leak Put 10 Million Stolen Email and Password Pairs on Telegram
HEROIC analysts identified a large-scale stealer log circulating on Telegram on January 23, 2025, cataloged as TXTLOG_ALIEN - 703. The log contained roughly 43 million total records, from which approximately 10,078,573 unique entries were extracted. Each record includes an email address, a plaintext password, and a homepage URL pointing to the site where the credential was captured. The data was shared openly in a Telegram channel, making it immediately accessible to any threat actor who wanted it.
Why Plaintext Passwords Make This Especially Dangerous
Most breaches involve hashed passwords, which at least require some effort to crack. This log does not. Every password in TXTLOG_ALIEN - 703 is stored in plaintext, meaning an attacker can read it directly without any additional tools. If your email and password appear in this file, anyone who downloads it can attempt to log in to your accounts right now. No decryption required. The homepage URLs also reveal exactly which websites were targeted, giving attackers a ready-made list of where to try those credentials first.
What Was Exposed in the TXTLOG_ALIEN - 703 Log
- Email addresses (approximately 10 million unique)
- Plaintext passwords tied directly to each email address
- Homepage URLs indicating the source sites where credentials were harvested
Why This Matters: From One Leaked Password to Full Account Takeover
Stealer logs like this one are the raw material for credential stuffing attacks. Automated bots take each email and password pair and test them across hundreds of services simultaneously: banking apps, email providers, shopping accounts, corporate VPNs. Because most people reuse passwords, a single exposed credential can open doors far beyond the original site. Once attackers are inside an email account, they can reset passwords on every other service tied to that address, enabling identity theft, financial fraud, and access to sensitive personal or business data.
How Stealer Logs Work
A stealer log is produced by infostealer malware that infects a device, typically through a malicious download, phishing email, or compromised software installer. Once running, the malware silently scans the device for saved browser credentials, stored passwords, and session cookies. It packages everything it finds into a structured log file and sends it back to whoever is controlling the malware. These logs are then sold, traded, or posted on Telegram channels and dark web forums, often within hours of collection. The ALIEN series of logs follows this pattern, with hundreds of batches released in sequence across January 2025.
Check If Your Email Appeared in This Breach
HEROIC's free breach scanner checks your email address against a database of more than 400 billion compromised records, including stealer logs from Telegram and dark web sources. If your credentials appeared in TXTLOG_ALIEN - 703 or any similar log, you will see it. Run a free scan at HEROIC to find out where your data has been exposed and get clear steps on what to do next.
Breach Breakdown
10,078,573 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds