Credentials, devices and data found in dark web stealer logs & breaches
Last updated
· most recent exposure 53 days ago
27
Exposure level: Moderate
manage.py scores 27/100 on credential volume, active device compromise, how recent the exposure is, and how much of it is employee rather than customer data.
Higher exposure than 10% of the 1,761 domains we track
Findings summary
Generated from this report’s data · 17 September 2026
Records for manage.py show limited exposure across dark web stealer logs and breach data, with 3 leaked credentials and 3 compromised devices recovered to date. The most recent record dates from 53 days ago.
The exposure is weighted towards staff accounts. 2 credentials belong to @manage.py accounts, which authenticate to internal systems rather than to a consumer service — the sharper of the two risks. Those accounts appear against GitHub among others — third-party services that sit outside the network boundary.
3 devices associated with manage.py were infected with credential-stealing malware.
Password hygiene is weak — 100% reuse a top-10 pattern, which makes credential stuffing against other services the likely next step.
Most recent exposure 53 days agoLast 90 days 0%100% reuse a top-10 password
Employee exposure
corporate accounts — @manage.py
2
leaked credentials · 2 compromised devices
Top exposed employee accounts
manage.py2
Where staff accounts were caught
github.com2
Customer exposure
stolen logins for manage.py
1
leaked credentials · 1 compromised devices
Top exposed customer accounts
58728107813819852291
3
Exposed Credentials
3
Compromised Devices
0
Credit Cards
0
Crypto Wallets
0
Auth Tokens
0
Stolen Cookies
Exposure over time (credentials leaked per month)
What this means. Each bar counts credentials first seen in that month.
A rising tail points to active, ongoing infections rather than a single historical breach —
the two call for different responses.
2026-022026-07
Corporate SaaS & shadow-IT exposed (employee logins to third-party services)
What this means. Third-party services staff signed into using a
manage.py address. Each one is an authentication path into company data that sits
outside the corporate perimeter, and outside most offboarding processes.
GitHub2
Most common passwords 100% reuse a top-10 password
ru***er2
ra***ma1
Frequently asked about manage.py
Has manage.py been breached?
We have recovered 3 credentials associated with manage.py from dark web stealer logs and breach collections, along with 3 compromised devices. That is not the same as a confirmed breach of manage.py's own systems: most stealer-log credentials come from malware on individual users' devices rather than from a compromise of the company itself.
Is my manage.py password leaked?
This report is aggregate and does not identify individuals. To check a specific address, run a free individual check from the ShadowMap home page — results are not stored.
How recent is this manage.py data?
The most recent exposure for manage.py was recorded 53 days ago. This report was compiled on 17 September 2026 and is refreshed periodically as new data arrives.
What should manage.py do about this exposure?
Force a password reset on the exposed accounts, and re-image the 3 compromised devices, which will otherwise keep leaking new credentials.