The APRIL 1 – 1230 LOGS Leak Exposed 21,991 American Accounts on Telegram
HEROIC analysts flagged a stealer log file uploaded to a public Telegram channel on December 26, 2023, under the name "APRIL 1 - 1230 LOGS." The dataset contains 21,991 records pulled from compromised endpoints in the United States, each containing an email address, a plaintext password, and URLs corresponding to the web services those victims were actively using. The passwords in this leak were captured directly off infected machines -- never hashed, never encrypted -- and made freely available to anyone following the Telegram channel where the file was posted.
The APRIL 1 - 1230 LOGS Leak Exposed 21,991 American Accounts to Immediate Takeover
The country field on this breach is United States, which narrows the affected population and makes this a concentrated threat against American internet users. With 21,991 working email and plaintext password combinations now in circulation, anyone who obtained this log from Telegram can attempt to access US-based accounts at email providers, financial institutions, retail platforms, healthcare portals, and workplace systems. Americans are disproportionately targeted by credential stuffing attacks because of the high value associated with US-based financial accounts and the widespread use of English-language platforms. The URLs in this log make targeting even easier by revealing exactly which services each victim was using, so attackers can prioritize high-value accounts like bank logins or payroll portals first. The combination of country-specific targeting and ready-to-use plaintext credentials makes this a particularly actionable dataset for criminals focused on US victims.
What Was Exposed in the APRIL 1 - 1230 LOGS Leak
- Email Addresses
- Plaintext Passwords
- URLs (API hosts, login portals, and web services accessed from compromised US devices)
Why US Victims in This Leak Face Compounding Financial and Identity Risks
For Americans whose credentials appear in this dataset, the risks are both immediate and long-lasting. Credential stuffing attacks against US banking and payment platforms can result in unauthorized wire transfers, fraudulent credit card charges, and drained savings accounts -- sometimes within hours of the credentials being tested. Identity theft from a compromised email account can lead to fraudulent loan applications, tax return fraud filed in the victim's name, and damage to credit scores that takes years to repair. The fact that this log was uploaded in December 2023 and contains data labeled "APRIL 1" suggests the credentials were collected months before the public release, meaning they may have already been exploited privately before becoming widely available. Victims who have not changed their passwords since that period remain at risk right now. Recieving a notification from a bank or credit service about suspicious activity is often the first sign someone's credentials from a leak like this have been put to use.
How Stealer Log Malware Targets US Endpoints
Infostealer malware does not discriminate by geography, but its operators often target users in high-income countries like the United States because the credentials harvested there tend to be worth more on criminal markets. The malware typically spreads through phishing emails crafted to look like shipping notifications, tax documents, or HR communications -- themes that are especially effective against US users. Once installed on a device, it silently extracts saved browser passwords, session cookies, autofill data, and credentials from local applications. Everything gets packaged into a log file like the "APRIL 1 - 1230 LOGS" dataset and sent to a server controled by the attacker. From there, the attacker may sell access to the log privately, use the credentials themselves, or eventually dump the data publicly on Telegram when it has been fully exploited. The December 2023 public upload suggests this data had already gone through at least one round of private monetization before reaching a broader audience. Victims typically have no idea their device was ever infected, and the malware often removes itself after completing the harvest to avoid detection.
Check If Your US Account Was Exposed in This Telegram Dump
If you are based in the United States and think your email address or passwords may have been caught in this or any similar stealer log, HEROIC's free breach scanner at heroic.com can help you find out. HEROIC indexes over 400 billion compromised records from stealer logs, dark web marketplaces, and major breach compilations -- including datasets like this one targeting American users. Searching your email address takes only a few seconds and can tell you definitaly whether your credentials have appeared in known leaks, so you can take action before an attacker does.
Breach Breakdown
21,991 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds