[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f395pbmfvgk4bj":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":20,"affectedCount":20,"affectedCountStatus":21,"affectedCountLowerBound":22,"affectedCountUnit":23,"hasEnglishDescription":4,"severity":24,"dataClasses":25,"description":28,"seoTitle":10,"seoTitleEn":8,"seoDescription":10,"seoDescriptionEn":29,"logoUrl":30,"isVerified":4,"isSensitive":31,"isSpamList":31,"isMalware":31,"company":32},"68e3266eda11adda48825390","TelegramStealerLogs","Stealer Logs Posted to Telegram Malware Exposure","stealer-logs-posted-to-telegram","","2024-07-18T00:00:00.000Z","2024-08-01T05:38:53.000Z","2025-03-04T02:06:27.000Z","2026-07-19T15:13:13.807Z","Malware","https:\u002F\u002Fwww.troyhunt.com\u002Fbegging-for-bounties-and-more-info-stealer-logs\u002F",[16,18,19],"https:\u002F\u002Fattack.mitre.org\u002Ftechniques\u002FT1555\u002F003\u002F","https:\u002F\u002Fattack.mitre.org\u002Ftechniques\u002FT1056\u002F",26105473,"known",null,"email_identifiers","Critical",[26,27],"Email addresses","Passwords","\u003Cp>Stealer logs collected from Telegram channels in July 2024 contained \u003Cstrong>26,105,473 unique email addresses\u003C\u002Fstrong> and passwords. This record is not a breach of Telegram's user database or of the services named in the logs; malware running on infected devices collected the data.\u003C\u002Fp>\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\u003Cp>The only verified data classes for this record are \u003Cstrong>email addresses and passwords\u003C\u002Fstrong>. Names, usernames, phone numbers, physical addresses, private messages, and Telegram account details are not verified classes. Combining an email address with a password increases the risk of account takeover, credential stuffing, and targeted phishing.\u003C\u002Fp>\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\u003Cp>The 22 GB corpus consisted only of stealer logs shared in malicious Telegram channels; previous combolist records were not included in this set. Although 89.7% of the email addresses had appeared in earlier breaches, 2,679,550 addresses were new. Malware running on infected machines created the logs by capturing credentials used across different websites. Responsibility therefore cannot be attributed to one website, company, or Telegram.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>People whose email address matches this corpus face the greatest risk, especially those who reused a password across services or stored passwords in a browser on an infected device. For people using corporate email, stolen credentials may also be tested against work systems as well as personal accounts.\u003C\u002Fp>\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\u003Cp>First isolate the suspicious device and \u003Cstrong>clean it before changing passwords\u003C\u002Fstrong>; otherwise a new password may be stolen again. Update the operating system and browsers, run a trusted malware scan, and remove suspicious extensions. Then use a clean device to replace critical passwords beginning with email, close active sessions, and enable two-step verification.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>Use a password manager to generate a unique password for every service, and protect the email account with strong authentication and current recovery options. Review device security, browser extensions, and downloaded files regularly; organizations should monitor unusual sign-ins and suspicious sessions that succeed on the first attempt.\u003C\u002Fp>\u003Ch2>Check Your Data\u003C\u002Fh2>\u003Cp>A match with this record means your email address appears in the stealer-log corpus and indicates a possible device infection. The result does not identify the affected website or password by itself, and it does not mean that your Telegram account or the companies where you used the address were breached. Address device cleanup and account security together.\u003C\u002Fp>","Stealer Logs Posted to Telegram Malware Exposure. 26.1 Million email identifiers were reported. Reported data: Email addresses, Passwords. Review the scope…","\u002Fuploads\u002Flogo\u002Ftelegram_stealer_logs.webp",false,{"name":33,"sector":34,"country":10,"website":10,"websiteArchiveUrl":10,"websiteStatus":10,"websiteCheckedAt":22},"Stealer Logs Posted to Telegram","Cybercrime \u002F Malware"]