Dark Web Exposure for shodan.io
Credentials, devices and data found in dark web stealer logs & breaches
80
Exposure level: Critical
shodan.io scores 80/100 based on leaked credentials, compromised devices, and stolen financial & session data found on the dark web.
Most recent exposure 20 days ago
Last 90 days +11%
3% reuse a top-10 password
Employee exposure
corporate accounts — @shodan.io
4
leaked credentials · 3 compromised devices
Top exposed employee accounts
shodan.io2
shodan.io/home1
thomsp***@shodan.io1
Where staff accounts were caught
serials.ws1
teamviewer.com1
websecu.epitech.eu1
www.hdb.com1
Customer exposure
stolen logins for shodan.io
75,161
leaked credentials · 1,314 compromised devices
Top exposed customer accounts
oldbaldf***@hotmail.com84
494785375
oldbaldfool72
milicell71
bmbng130354
Most targeted services
account.shodan.io74,498
unt.shodan.io14
nt.shodan.io9
cccount.shodan.io8
mccount.shodan.io7
75,165
Exposed Credentials
Exposure over time (credentials leaked per month)
2024-012026-05
Most common passwords 3% reuse a top-10 password
my***27227
ca***t1134
12***89132
k@***z5115
ru***20114
MT***10107
tu***os103
1s***er102
ro***27101
12***78100
Stolen sessions (active cookies that can bypass MFA)
youtube.com38,748
google.com17,349
bing.com13,485
adnxs.com11,089
criteo.com8,694
pubmatic.com8,418
Compromised despite antivirus (AV installed on infected devices)
Windows Defender42
Avast Antivirus5
360 Total Security3
ESET Security3
Norton Security2
iolo Antivirus2
Financial, crypto & app tokens
Crypto wallets
generic2
metamask2
atomic1
electrum1
App / session tokens
Google446
Discord62
Telegram4
Where devices were compromised (by country)
Mexico [MX]13
Colombia [CO]9
Peru [PE]4
Argentina [AR]3
IN3
Top cities
Bogotá4
Mexico City3
San Luis Potosí City3
Cúcuta2
Guayaquil2
Browsers & apps affected
Edge [Default]37
Google Chrome (Default)35
Google Chrome [Profile 7]32
Chrome [Default]31
Microsoft Edge (Default)31
Browser/Logins/Edge_Default[ea2d989b].txt20
Stealer malware families seen
RedLine
Figures are aggregate counts derived from dark web stealer logs and public breach data.
Data is indicative and updated periodically.