Our Analysts Found the USA MIX VALID MOON Dump Circulating in Private Telegram Channels
HEROIC analysts found the USA MIX VALID MOON dataset circulating in private Telegram channels in February 2026, when monitoring of stealer log distribution networks flagged it as a newly uploaded credential archive. The file contained 847 records comprising email addresses, plaintext passwords, and endpoint URLs sourced from US-based accounts. The VALID designation in the archive name indicates the credentials were verified as active prior to distribution -- meaning the email/password pairs were tested against live systems before being packaged for sale or sharing on Telegram.
Why a VALID-Labeled Stealer Log Is a Concentrated Threat
The VALID label in this archive's name is a critical detail. Unlike raw stealer logs that contain a mix of current and outdated credentials, a VALID collection has been pre-screened -- an attacker or broker has already tested the email/password pairs and confirmed they work on live accounts. This means every record in the USA MIX VALID MOON dataset represents an active, confirmed unauthorized access risk. The 847 records are smaller in volume than bulk ULP dumps, but they are densely dangerous: each one is a working key to a real account. US-targeted validated credential sets are among the most valueable categories of stolen data on the Telegram marketplace because of the concentration of high-value financial and corporate accounts in the target pool.
Data Exposed in the USA MIX VALID MOON Archive
The 847 records in this validated credential dataset contained the folowing catagories of compromised information:
- Email Addresses -- US-based victim account identifiers, pre-screened for active status
- Plaintext Passwords -- verified working credentials requiring no decryption or validation
- URLs -- the specific login endpoints associated with each confirmed active credential
Account Takeover, Identity Theft, and Financial Fraud in a US-Targeted Dataset
Validated US-based credential sets are particularly attractive to financially motivated threat actors because American accounts often have access to banking platforms, credit services, investment accounts, and e-commerce profiles with stored payment methods. With credentials confirmed as active, attackers bypass the credential stuffing step and move directly to account exploitation. They access financial accounts to initiate transfers or purchases, leverage email access to intercept two-factor codes and password reset messages for linked accounts, and accumulate personal information for identity theft. The concentrated nature of a validated set means each record delivers a higher return on criminal investment than an unverified bulk dump. Even 847 active US accounts can generate significant fraudulent activity if each provides access to financial or identity-linked platforms.
How VALID Credential Collections Are Built and Distributed on Telegram
VALID stealer log collections like USA MIX VALID MOON are assembled through a multi-stage process. Raw credential logs are first harvested by infostealer malware families including LummaC2, RedLine, and Vidar, which silently collect saved browser passwords from infected machines. Operators or brokers then run the raw credential lists through automated checking tools that test each email/password pair against live login endpoints. Records that return a successfull login are flagged as valid and separated into a premium collection. These validated subsets are smaller but command higher prices in the dark web credential marketplace. The MOON label may indicate the operator's brand or the specific checking tool used. These collections circulate through private Telegram channels accessible only to paying subscribers or trusted members of criminal networks, reducing public visibility and delaying detection.
Our Analysts Found the USA MIX VALID MOON Dump Circulating in Private Telegram Channels
HEROIC's monitoring infrastructure tracks private Telegram channels and dark web sources to detect newly surfaced credential datasets before they are widely exploited. The USA MIX VALID MOON archive was identified and indexed in our breach database, which now covers more than 400 billion compromised records. Enter your email address in HEROIC's free breach scanner to check whether your credentials appeared in this dataset or any other collection we have catalogued. If your data is found, update affected passwords immediately and activate two-factor authentication. For US-based accounts appearing in a validated collection like this one, speed of response is critical -- these credentials were confirmed active and are being actively exploited.
Breach Breakdown
847 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds