28,943 Records from BHF FREE Leaked in Stealer Log Attack on Telegram
A Telegram user uploaded a stealer log file labeled "BHF FREE" on April 6, 2025, exposing 28,943 records of stolen credentials to anyone with access to the channel. The file contained plaintext passwords, email addresses, and API host URLs harvested directly from infected endpoints, which means the data was immediately usable with no additional processing required. Stealer logs of this size don't stay private for long, and the damage spreads fast once they're out in the open.
Why This Is Dangerous
With nearly 29,000 records in a single upload, this is one of the larger stealer log compilations to surface recently. Each record contains a working email and password combination, meaning attackers have a ready-made list for credential stuffing attacks against email providers, banking platforms, social media, and any other service where people reuse passwords. The barrier to entry for exploiting this data is essentially zero.
The API host URLs buried in this log are a serious secondary concern. API credentials are often more privileged than regular user logins and can provide access to databases, cloud infrastructure, and development environments. An attacker who finds valid API credentials in a dump like this has a lot more leverage than someone who just cracked a social media password.
The BHF FREE label suggests this data may have been shared at no cost, which is a common tactic to build credibility in underground communities or to dump data that's already been monetized elsewhere. Either way, the credentials are now freely circulating and the risk to affected users is ongoing.
What Was Exposed
- Email addresses tied to active user accounts
- Plaintext passwords with no encryption or hashing
- API host URLs and associated access credentials
- Endpoint device information and identifiers
- Login URLs for web services and applications
- Browser-harvested session data and saved credentials
- Authentication tokens from infected device sessions
- Usernames and account identifiers accross multiple services
Why This Matters
Nearly 29,000 people had their credentials harvested and handed out for free on a public Telegram channel. For each of those individuals, every account they've ever used with that password is now at risk. And because many people don't change passwords until something goes visibly wrong, those accounts could remain vulnerable for months or years after the initial infection.
This log was attributed to United States-based endpoints, putting domestic users at the center of the exposure. But credential stuffing tools are automated and global, so attackers from anywhere can be testing these logins against services right now. The longer affected users go without changing passwords, the more likely it is that one of those accounts has already been accessed without their knowledge.
How Stealer Log Works
Infostealer malware most commonly reaches victims through pirated software, fake browser extensions, malicious email attachments, or compromised download links. Once it executes on a device, it scans for stored credentials in browsers like Chrome and Firefox, standalone password managers, and application config files. The whole operation typically completes in under a minute.
The harvested data is packaged into a log file and sent back to the attacker's server, where it gets sorted and either sold or shared. In this case, the log was uploaded to a Telegram channel under the name BHF FREE, indicating it was distributed at no cost. This is a fairly common tactic, where older or already-monetized logs get shared publicly to generate goodwill in underground communities or simply dumped when the attacker has moved on.
What makes this category of attack so persistant is that it doesn't require any vulnerability in the services whose credentials get stolen. The weakness is in the endpoint itself. The email provider or banking app did nothing wrong. Their users just had infected devices, and that was enough for the malware to capture everything and send it out.
Check If You Were Affected
If you think your credentials may have been caught up in the BHF FREE stealer log or any similar upload, check your exposure now using HEROIC's free breach checker at heroic.com. Enter your email address to see which breaches you've appeared in and what data was exposed, so you can take action before someone else does.
Breach Breakdown
28,943 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds