12,585 Records from 1.8 LOGS_CENTEER Leaked in Stealer Log Attack
On July 31, 2022, a stealer log file called "1.8 LOGS_CENTEER" was shared publicly on Telegram, exposing 12,585 records belonging to real users. The file contained email adresses, plaintext passwords, and URLs harvested from infected devices, handed directly to anyone willing to download it. This kind of leak doesn't require a hacker to crack anything. The damage is already done before most victims ever find out.
Why This Is Dangerous
Unlike breaches that involve hashed passwords or encrypted databases, stealer logs deliver credentials in ready-to-use form. The plaintext passwords in this file mean any attacker who grabbed the upload could immediatly begin testing logins across email platforms, banking sites, and corporate systems without any additional effort.
Telegram channels can accumulate thousands of subscribers in a short period, so files posted there spread fast. This particular log was publicly accessible, meaning the exposure wasn't limited to a small criminal circle but potentially reached a wide and varied audience of bad actors.
What makes this particularly alarming is that stealer logs are often fresher than traditional database dumps. The credentials were recently active on infected machines, which makes them more likely to still work at the time of exposure.
What Was Exposed
- Email addresses linked to active user accounts
- Plaintext passwords with no obfuscation or hashing
- URLs indicating which websites and services were accessed
- API host data from connected application environments
- Endpoint information from the compromised devices themselves
- Potential browser session data captured during active use
- Login metadata that could reveal patterns of account usage
Why This Matters
With 12,585 records exposed, this isn't a small or isolated incident. Each record represents a person whose credentials were stolen from their own device without their knowledge. If any of those people reuse passwords accross multiple services, which most people do, attackers gained access to far more than just one account per victim.
The Telegram upload format also means this data was shared freely rather than sold privately. Files distributed this way tend to get downloaded, copied, and redistributed across multiple platforms, extending the window of risk well beyond the original upload date.
How Stealer Log Works
Stealer log malware is typically delivered through malicious downloads, fake software cracks, or phishing links that trick users into running an infected file. Once active on a device, the malware scans for saved credentials in browsers, email clients, and password managers, then silently bundles everything into a structured log.
That log file is then transmitted back to the attacker's infrastructure and often sorted by country, email domain, or service type before being packaged for sale or redistribution. In this case, the log file was uploded directly to a public Telegram channel, making it available to anyone with access to the link.
The stealer operates entirely in the background and leaves minimal traces, which is why victims rarely know their credentials have been taken until they notice suspicious account activity or find their data in a breach checker.
Check If You Were Affected
If you think your credentials may have been part of the 1.8 LOGS_CENTEER stealer log leak, don't wait around to find out. Use HEROIC's free breach checker at heroic.com to search your email address against known breach and stealer log databases. If your data shows up, change your passwords immediately and enable two-factor authentication wherever possible.
Breach Breakdown
12,585 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds