ShadowMap

Dark Web Exposure for login.action

Credentials, devices and data found in dark web stealer logs & breaches
58
Exposure level: High
login.action scores 58/100 based on leaked credentials, compromised devices, and stolen financial & session data found on the dark web.
Most recent exposure 4 days ago Last 90 days -89% 6% reuse a top-10 password
Employee exposure
corporate accounts — @login.action
14,696
leaked credentials · 665 compromised devices
Top exposed employee accounts
www.evernote.com/login.action943
8443/guestportal/login.action486
8443/login.action187
8090/login.action163
7080/bteb_web/login.action105
Where staff accounts were caught
https6,971
http1,107
evernote.com767
c487
www.evernote.com298
Customer exposure
stolen logins for login.action
165
leaked credentials · 101 compromised devices
Top exposed customer accounts
lindanne0***@gmail.com28
tina.servaia28
500488920
admin12
01b76911
Most targeted services
evernote.com.login.action28
healthkart.com.auth.login.action28
u9419rtevgalid.login.action8
sensaelimumsingi.tamisemi.go.tz.dhis-web-commons.security.login.action3
wcb.8.login.action3
14,861
Exposed Credentials
676
Compromised Devices
0
Credit Cards
0
Crypto Wallets
0
Auth Tokens
43
Stolen Cookies

Exposure over time (credentials leaked per month)

2024-012026-07

Corporate SaaS & shadow-IT exposed (employee logins to third-party services)

Cisco116

Most common passwords 6% reuse a top-10 password

1q***@W98
kh***2895
(h***ps90
us***bU77
@A***3476
St***f!76
go***2276
qw***!@72
51***1071
Te***2055

Stolen sessions (active cookies that can bypass MFA)

tiktok.com23
booking.com14
reddit.com6

Browsers & apps affected

android:dhis2.com1

Related companies

Explore

Check your own exposure →

Free dark web & attack-surface check by ShadowMap

Figures are aggregate counts derived from dark web stealer logs and public breach data. Data is indicative and updated periodically.