US Users Targeted: USA4 Stealer Log Exposes 151 Passwords
HEROIC analysts discovered a stealer log titled "USA4" that was uploaded to a Telegram channel on July 5, 2026. The dump contains 151 records of US-targeted credentials, each pairing an email address with a plaintext password and the URLs visited during the malware infection. The sequential naming convention ("USA4") suggests this is the fourth installment in a series of US-focused credential dumps from the same distributor.
While 151 records may appear small, the serial nature of these releases means the same attacker is likely accumulating thousands of American credentials over time. Each new installment adds fresh, recently stolen data to a growing pool of exploitable accounts.
Why Plaintext Passwords Are the Worst-Case Scenario
Every password in this dump is stored in plaintext. There are no password hashes to crack, no encryption layers to bypass, and no technical barriers between the file and a successful login attempt. Anyone who downloads this dump from Telegram can start testing credentials within seconds using nothing more than a web browser.
The plaintext format also means that password complexity offers no protection. Even strong, lengthy passwords with special characters are fully visible in the file. The only defense for affected users is to change their passwords before an attacker uses them, which is a race against time once the file goes public on Telegram.
What Was Exposed in the USA4 Dump
- Email Addresses — US-based email accounts that serve as primary login identifiers for banking, shopping, social media, and professional platforms.
- Plaintext Passwords — Unencrypted passwords stolen directly from browser credential stores, requiring no processing to use in login attempts.
- URLs — Website addresses that victims were accessing when the malware intercepted their sessions, identifying which platforms each credential unlocks.
Why 151 Fresh Credentials Pack a Larger Punch Than Expected
Fresh credentials carry more weight than aged ones because the passwords are more likely to still be active. The USA4 dump was uploaded in July 2026 with recently harvested data, meaning many of these passwords have not yet been changed by their owners. Attackers prioritize fresh stealer logs precisely because the success rate for login attempts is significantly higher.
Each of the 151 credentials will be tested across multiple platforms through credential-stuffing attacks. With password reuse rates exceeding 60%, attackers can reasonably expect to access two to three additional accounts per credential, potentially reaching over 400 accounts from this single dump. The financial and personal impact of that many compromised accounts adds up quickly.
How Stealer Logs Build a Series of US-Focused Dumps
Infostealer malware continuously harvests credentials from infected devices, feeding a steady stream of stolen data to the attacker's servers. Rather than releasing everything at once, some distributors break their collections into numbered batches, releasing a new installment every few days. This keeps their Telegram channels active and builds a following among buyers looking for fresh data.
The "USA4" label indicates this particular distributor has been operating for some time, building a catalog of US-targeted credential files. Each batch likely comes from a different set of recently infected devices, ensuring that the credentials are current. This serial distribution model makes it easy for attackers to subscribe to a steady supply of exploitable American accounts.
Check If Your Credentials Were Exposed
If you live in the United States and use a web browser to save passwords, your credentials could have been harvested by infostealer malware and included in the USA4 dump. HEROIC offers a free breach scanner that searches your email address against over 400 billion compromised records from stealer logs, data breaches, and dark web leaks.
Check your email now to determine whether your credentials were captured in this dump or any other known breach. If a match is found, change your password immediately on all affected accounts and enable two-factor authentication to add a critical barrier against unauthorized access.
Breach Breakdown
151 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds