United States Breach: 516 Aon.com Logins, Passwords Exposed
In June 2026, HEROIC's dark web analysts tracked a stealer log file uploaded to Telegram on 10-Jun-2026 that contained 516 records linked to aon.com. The log included email addresses, plaintext passwords, and the URLs of the login pages those credentials were captured from, the kind of data malware quietly scrapes off an infected device before an attacker packages it up for sale or free distribution on Telegram.
Why This Aon.com Stealer Log Is Dangerous
Unlike a typical company data breach, a stealer log comes straight from an infected computer. Because the passwords are stored in plaintext and paired with the exact URL they were used on, anyone who gets hold of this file can log straight into the matching account with no guessing, no cracking, and no delay. That combination of email, password, and destination URL is essentially a ready-made key ring.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the sites the credentials were used on
Why This Matters
Because the passwords were stored as plaintext, this is not a case of hashed data that would need to be cracked first. Anyone in possession of the log can attempt to sign in immediately. If any of the 516 affected people reused these same email and password combinations on other sites, those accounts are also at risk through credential stuffing, where attackers automate login attempts across many platforms using leaked credential pairs.
How Stealer Logs Work
Stealer logs come from malware that infects a device, often through a fake download, cracked software, or a malicious email attachment. Once running, the malware quietly copies saved browser passwords, autofill data, and session details, then sends everything back to the attacker. The stolen data is bundled into a text file, or "log," and shared or sold, in this case uploaded directly to a Telegram channel where anyone can download it.
Check If You Are Affected
If you use an aon.com email address or have ever logged into an account tied to it, it is worth checking whether your details showed up in this log. HEROIC's free breach scanner searches a database of more than 400 billion leaked records to tell you in seconds if your email or passwords have been exposed, and helps you know exactly which accounts need a fresh password right now.
Breach Breakdown
516 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds