Who’s in the 28K Mix 06.06 Leak? 26,746 Accounts Exposed
In June 2026, HEROIC analysts identified a stealer log named "28K Mix 06.06" uploaded to a Telegram channel by a user sharing malware harvested credentials in bulk. Despite the "28K" label, the file HEROIC verified contained 26,746 records, each combining a login URL, an email address, and a plaintext password.
Who Is Targeted by the 28K Mix Log
Mixed domain logs like this one are not aimed at one company or service. Instead, they combine whatever an infected computer had saved across dozens of different sites, from email providers to shopping accounts to streaming services. That means anyone whose device was infected by the underlying malware could be swept into this log regardless of which sites they use.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Associated Login URLs
Why This Matters
With 26,746 ready-to-use credential pairs in circulation, this log is well suited to large-scale credential stuffing attacks, where criminals automate login attempts across many sites at once. Anyone in this file who reused a password on another account faces a real risk of account takeover.
How Stealer Logs Work
A mixed domain stealer log is built by combining data stolen from many infected devices, then sorting the saved logins by the sites they belong to rather than by the victim. Criminals distribute these logs in batches like the "28K Mix" file, often naming them by size and date so buyers on Telegram can quickly judge their value.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including mixed domain stealer logs like this one. Run a free scan to see if your credentials were part of this 26,746 record exposure.
Breach Breakdown
26,746 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds