Credentials, devices and data found in dark web stealer logs & breaches
Last updated
· most recent exposure 70 days ago
43
Exposure level: Elevated
login.sh scores 43/100 on credential volume, active device compromise, how recent the exposure is, and how much of it is employee rather than customer data.
Higher exposure than 27% of the 1,761 domains we track
Findings summary
Generated from this report’s data · 17 September 2026
The domain login.sh has limited credential exposure on the dark web, with 51 leaked credentials and 40 compromised devices recovered to date. Volume is falling — the last 90 days are down 63% on the preceding quarter, so much of this exposure is likely historical. The most recent record dates from 70 days ago.
The exposure is weighted towards staff accounts. 43 credentials belong to @login.sh accounts, which authenticate to internal systems rather than to a consumer service — the sharper of the two risks.
40 devices associated with login.sh were infected with credential-stealing malware.
95% of recovered passwords reuse a top-10 pattern, so credential stuffing against adjacent services should be assumed.
Most recent exposure 2026-07-08Last 90 days -63%95% reuse a top-10 password
Employee exposure
corporate accounts — @login.sh
43
leaked credentials · 32 compromised devices
Top exposed employee accounts
login.sh-netz.com/22
//login.sh-netz.com deni***@live.de6
8480/login.sh4
//login.sh-netz.com b-kroer***@live.de4
//login.sh-netz.com2
Where staff accounts were caught
upwork.com22
https13
183.89.40.1073
57830496c0fc.sn.mynetname.net2
192.168.1.121
Customer exposure
stolen logins for login.sh
8
leaked credentials · 8 compromised devices
Top exposed customer accounts
ala00alle***@vp.pl2
redbodegonrojas2
kelas5202111
missing-user1
peiramatiko1
51
Exposed Credentials
40
Compromised Devices
0
Credit Cards
0
Crypto Wallets
0
Auth Tokens
0
Stolen Cookies
Exposure over time (credentials leaked per month)
What this means. Each bar counts credentials first seen in that month.
A rising tail points to active, ongoing infections rather than a single historical breach —
the two call for different responses.
2024-012026-07
Most common passwords 95% reuse a top-10 password
th***de22
fa***4!6
Bl***304
Al***7@2
bo***212
/s***3/1
12***561
An***mx1
Su***581
Wo***661
Frequently asked about login.sh
Has login.sh been breached?
We have recovered 51 credentials associated with login.sh from dark web stealer logs and breach collections, along with 40 compromised devices. That is not the same as a confirmed breach of login.sh's own systems: most stealer-log credentials come from malware on individual users' devices rather than from a compromise of the company itself.
Is my login.sh password leaked?
This report is aggregate and does not identify individuals. To check a specific address, run a free individual check from the ShadowMap home page — results are not stored.
How recent is this login.sh data?
The most recent exposure for login.sh was recorded 70 days ago. This report was compiled on 17 September 2026 and is refreshed periodically as new data arrives.
What should login.sh do about this exposure?
Force a password reset on the exposed accounts, and re-image the 40 compromised devices, which will otherwise keep leaking new credentials.