Yahoo Users Targeted: 149,466 Passwords Exposed in New 66
In January 2023, HEROIC's dark web intelligence team discovered a stealer log collection titled Yahoo New 66 on a Telegram channel. The dump targets Yahoo email users specifically, containing 149,466 records that expose email addresses, plaintext passwords, and the URLs of services where credentials were stolen. This focused collection poses a severe threat to anyone who uses or has used a Yahoo email account.
No Encryption, No Safety Net
Every password in the Yahoo New 66 dump is stored in plaintext — completely unprotected and immediately exploitable. Attackers can read these passwords exactly as the victim typed them. With nearly 150,000 credentials exposed in this format, threat actors have a massive library of working logins that require zero technical effort to abuse.
What Was Exposed
- Yahoo email addresses linked to personal and business communications
- Plaintext passwords captured without any form of protection
- URLs documenting the websites and services where each credential was harvested
The Chain Reaction of Reused Yahoo Passwords
A compromised Yahoo password is rarely just a Yahoo problem. Attackers run credential stuffing campaigns that test each leaked email-password pair against financial platforms, e-commerce sites, healthcare portals, and corporate logins. Since Yahoo accounts often serve as recovery emails for other services, compromising a Yahoo login can give an attacker the keys to reset passwords on virtually every connected account. The 149,466 records in this dump create a web of risk that extends across the entire digital ecosystem.
Stealer Malware: The Engine Behind Yahoo New 66
This collection was generated by infostealer malware — programs such as RedLine, Vidar, and Aurora that infect devices through phishing links, pirated software, and drive-by downloads. Once embedded on a system, the malware silently harvests browser-saved credentials, records keystrokes, and captures login sessions. The resulting data is organized into log files, labeled by target (in this case Yahoo), and distributed through Telegram channels and underground forums for other criminals to exploit.
Check If Your Credentials Were Exposed
If you have ever used a Yahoo email account, your credentials could be in this dump. HEROIC maintains a breach scanner with over 400 billion compromised records spanning thousands of data breaches and stealer log collections. Search for your email address to see if it appears in Yahoo New 66 or any other breach. Act immediately on any findings: update your Yahoo password, enable two-factor authentication, and ensure you are not reusing that password elsewhere.
Breach Breakdown
149,466 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds