These files are usually generated through credential stuffing or malware logs (InfoStealers). The name "vienspechotesfiles" likely refers to the specific threat actor, automated script, or Telegram channel responsible for aggregating and "cleaning" the data for distribution on the dark web or hacking forums.
Any account using a password found in a public leak should be considered compromised. Change passwords immediately to unique, complex strings.
Exploiting saved payment methods for fraudulent purchases. Mitigation and Recommendations