Credentials, devices and data found in dark web stealer logs & breaches
Last updated
· most recent exposure 11 days ago
48
Exposure level: Elevated
aws.training scores 48/100 on credential volume, active device compromise, how recent the exposure is, and how much of it is employee rather than customer data.
Higher exposure than 36% of the 1,761 domains we track
Findings summary
Generated from this report’s data · 4 October 2026
The domain aws.training has moderate credential exposure on the dark web, with 146 leaked credentials and 88 compromised devices recovered to date. Volume is falling — the last 90 days are down 62% on the preceding quarter, so much of this exposure is likely historical. The most recent exposure was recorded 11 days ago.
Exposure is split across both sides: 37 employee credentials on the aws.training domain, and 109 stolen customer logins for its services. Those accounts appear against Microsoft 365 among others — third-party services that sit outside the network boundary.
Credential-stealing malware was found on 88 devices linked to aws.training; the RedLine and StealC families account for the identified strains.
50% of recovered passwords reuse a top-10 pattern, so credential stuffing against adjacent services should be assumed. The same devices also gave up 10 crypto wallets.
Most recent exposure 11 days agoLast 90 days -62%50% reuse a top-10 password
Employee exposure
corporate accounts — @aws.training
37
leaked credentials · 24 compromised devices
Top exposed employee accounts
oscar.go***@quipux.com-aws.training12
***@quipux.com-aws.training5
dari.de***@aws.training3
schau***@aws.training2
atoul***@aws.training2
Where staff accounts were caught
partnercentral.awspartner.com16
le.ac.uk2
www.fakturownia.pl2
www.kaba365.com2
www.zakonrf.info2
Customer exposure
stolen logins for aws.training
109
leaked credentials · 67 compromised devices
Top exposed customer accounts
moinuewah***@inbox.lv17
bellemyelo***@pmi.com8
sarette.bree***@simon.com6
tuckettmtvguide.com5
rogolgre***@core-mark.com4
Most targeted services
www.aws.training18
cdn.aws.training1
mail.aws.training1
146
Exposed Credentials
88
Compromised Devices
0
Credit Cards
10
Crypto Wallets
0
Auth Tokens
0
Stolen Cookies
Exposure over time (credentials leaked per month)
What this means. Each bar counts credentials first seen in that month.
A rising tail points to active, ongoing infections rather than a single historical breach —
the two call for different responses.
2024-012026-09
Corporate SaaS & shadow-IT exposed (employee logins to third-party services)
What this means. Third-party services staff signed into using a
aws.training address. Each one is an authentication path into company data that sits
outside the corporate perimeter, and outside most offboarding processes.
Microsoft 3651
Most common passwords 50% reuse a top-10 password
f6***ck17
dr***es10
IE***OI7
km***kC5
DD***jO4
gY***rs4
mz***qr4
By***F33
Kp***o93
ka***633
Financial, crypto & app tokens
Crypto wallets
generic4
bitcoin_core2
coinomi2
electrum1
monero1
Browsers & apps affected
Mozilla Firefox2
360 Browser [tDbX5zDIwo.default-release]1
360 Browser [zWCAWsVdqoO1.default-release]1
Chedot1
Maxthon Browser1
Vivaldi [EdX9GWyp.default-release]1
Stealer malware families seen
RedLineStealC
Frequently asked about aws.training
Has aws.training been breached?
We have recovered 146 credentials associated with aws.training from dark web stealer logs and breach collections, along with 88 compromised devices. That is not the same as a confirmed breach of aws.training's own systems: most stealer-log credentials come from malware on individual users' devices rather than from a compromise of the company itself.
Is my aws.training password leaked?
This report is aggregate and does not identify individuals. To check a specific address, run a free individual check from the ShadowMap home page — results are not stored.
How recent is this aws.training data?
The most recent exposure for aws.training was recorded 11 days ago. This report was compiled on 4 October 2026 and is refreshed periodically as new data arrives.
What should aws.training do about this exposure?
Force a password reset on the exposed accounts, and re-image the 88 compromised devices, which will otherwise keep leaking new credentials.