Breach Intelligence Report 10 Apr 2026

Our Analysts Found the USA MIX VALID MOON Dump Circulating in Private Telegram Channels

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs USA MIX VALID MOON uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 847
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts found the USA MIX VALID MOON dataset circulating in private Telegram channels in February 2026, when monitoring of stealer log distribution networks flagged it as a newly uploaded credential archive. The file contained 847 records comprising email addresses, plaintext passwords, and endpoint URLs sourced from US-based accounts. The VALID designation in the archive name indicates the credentials were verified as active prior to distribution -- meaning the email/password pairs were tested against live systems before being packaged for sale or sharing on Telegram.


Why a VALID-Labeled Stealer Log Is a Concentrated Threat

The VALID label in this archive's name is a critical detail. Unlike raw stealer logs that contain a mix of current and outdated credentials, a VALID collection has been pre-screened -- an attacker or broker has already tested the email/password pairs and confirmed they work on live accounts. This means every record in the USA MIX VALID MOON dataset represents an active, confirmed unauthorized access risk. The 847 records are smaller in volume than bulk ULP dumps, but they are densely dangerous: each one is a working key to a real account. US-targeted validated credential sets are among the most valueable categories of stolen data on the Telegram marketplace because of the concentration of high-value financial and corporate accounts in the target pool.


Data Exposed in the USA MIX VALID MOON Archive

The 847 records in this validated credential dataset contained the folowing catagories of compromised information:

  • Email Addresses -- US-based victim account identifiers, pre-screened for active status
  • Plaintext Passwords -- verified working credentials requiring no decryption or validation
  • URLs -- the specific login endpoints associated with each confirmed active credential

Account Takeover, Identity Theft, and Financial Fraud in a US-Targeted Dataset

Validated US-based credential sets are particularly attractive to financially motivated threat actors because American accounts often have access to banking platforms, credit services, investment accounts, and e-commerce profiles with stored payment methods. With credentials confirmed as active, attackers bypass the credential stuffing step and move directly to account exploitation. They access financial accounts to initiate transfers or purchases, leverage email access to intercept two-factor codes and password reset messages for linked accounts, and accumulate personal information for identity theft. The concentrated nature of a validated set means each record delivers a higher return on criminal investment than an unverified bulk dump. Even 847 active US accounts can generate significant fraudulent activity if each provides access to financial or identity-linked platforms.


How VALID Credential Collections Are Built and Distributed on Telegram

VALID stealer log collections like USA MIX VALID MOON are assembled through a multi-stage process. Raw credential logs are first harvested by infostealer malware families including LummaC2, RedLine, and Vidar, which silently collect saved browser passwords from infected machines. Operators or brokers then run the raw credential lists through automated checking tools that test each email/password pair against live login endpoints. Records that return a successfull login are flagged as valid and separated into a premium collection. These validated subsets are smaller but command higher prices in the dark web credential marketplace. The MOON label may indicate the operator's brand or the specific checking tool used. These collections circulate through private Telegram channels accessible only to paying subscribers or trusted members of criminal networks, reducing public visibility and delaying detection.


Our Analysts Found the USA MIX VALID MOON Dump Circulating in Private Telegram Channels

HEROIC's monitoring infrastructure tracks private Telegram channels and dark web sources to detect newly surfaced credential datasets before they are widely exploited. The USA MIX VALID MOON archive was identified and indexed in our breach database, which now covers more than 400 billion compromised records. Enter your email address in HEROIC's free breach scanner to check whether your credentials appeared in this dataset or any other collection we have catalogued. If your data is found, update affected passwords immediately and activate two-factor authentication. For US-based accounts appearing in a validated collection like this one, speed of response is critical -- these credentials were confirmed active and are being actively exploited.

Breach Breakdown

Domain USA MIX VALID MOON uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 10 Apr 2026
Check in 5 seconds

847 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,218 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $6.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance