Leaked credentials ( emails and passwords , etc...)
None
Vulnerability Details
# Summary
Hi i'm a CTI analyst And Bug bounty Hunter , I found A lot of credentials for your domain
on the Telegram bot: `https://t.me/HaveIBeenHacked_Bot`
While the exact sources of the leaked data are unknown, the volume of exposed information is substantial. This report is submitted for your review to assess and mitigate the exposure of user credentials, including emails and passwords.
## Note
I did not attempt to use the token to verify its validity, so I do not know if the password is valid. Upon discovering it, I promptly reported it for your review.
# Leaked Data
-**Since the credentials are related to customers' PII—emails and passwords—I kindly request that you discuss the issue with the company team before taking any action**.
████
## Impact
- **Exposure of user emails and passwords**, leading to credential compromise.
- **Increased risk of account takeover (ATO)** if users reuse passwords across platforms.
- **Potential for phishing and social engineering** attacks targeting affected users.
- **Reputational damage** due to leaked user data.
- **Regulatory and compliance risks**, depending on applicable data protection laws.
Actions
View on HackerOneReport Stats
- Report ID: 3091909
- State: Closed
- Substate: resolved
- Upvotes: 4