AuroraLogsTeam 1611count: 112,523 US Records — The Largest Single Batch
112,523 Records, 1,611 Devices: AuroraLogsTeam's Largest Single Release Analyzed
On March 25, 2025, AuroraLogsTeam released two batches in a single day. The 1611count batch and the 1021count batch arrived simutaneously, together exposing over 164,000 US records in 24 hours. The 1611count batch was the larger of the two -- and the largest individual release in the entire AuroraLogsTeam March 2025 campaign. With 112,523 records harvested from 1,611 infected devices, and an average credential density of approximately 70 records per device, this batch was remarkably dennse in comparison to other releases in the series. The impackt on affected users was immediate: every credential extracted was in plaintext, ready to use.
AuroraLogsTeam 1611count (March 2025): Breach Summary
- Records Exposed: 112,523
- Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
- Breach Type: Stealer log
- Device Count (PCS): 1,611 infected devices
- Password Type: Plaintext -- directly usable with no cracking required
- Country: United States
- Date Leaked: March 25, 2025
Highest Credential Density in the Series: What 70 Records Per Device Means
A per-device credential density of approximately 70 records means the average infected machine in the 1611count batch had 70 sets of email/password pairs stored in its browser credential vaults. For context, the March 20 231count batch averaged about 49 credentials per device, and the March 21 281count batch averaged approximately 58. The 1611count batch's 70 per-device average suggests targeting of high-value, credential-dense machines -- likely active professionals or frequent online shoppers with extensive saved login libraries. Machines with dense credential stores are disproportionately valuable to threat actors executing credential stuffing campaigns at scale.
The March 25 Dual Release: 1611count and 1021count Together
The simultaneous release of 1611count and 1021count on March 25 was the single highest-volume day in AuroraLogsTeam's documented March 2025 activity. The combined total for the day was 164,639 records from 2,632 infected devices. This dual-drop pattern -- also seen on March 20 with the 726count and 231count batches -- suggests AuroraLogsTeam maintained multiple concurrent collection pipelines, aggregating results and releasing them in synchronized batches rather than a continuous stream. The March 25 dual release represented the operational peak of the campaign before the March 27 1595count release closed things out.
API Host Data and Enterprise Attack Surface
Among the data types included in the 1611count dataset is API host data -- records capturing the API endpoints and hostnames that infected devices had active credentials for at the time of compromise. This category of data extends the risk profile beyond individual consumer accounts. API credentials harvested from developer machines, corporate laptops, or SaaS-connected workstations can provide access to backend systems, CI/CD pipelines, cloud infrastructure, and business intelligence platforms. In a batch as large as 112,523 records, even a small percentage of API credentials represents a significant enterprise attack surface.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to help you identify whether your credentials appear in the AuroraLogsTeam 1611count release or any related stealer log operation. With 112,523 plaintext records in circulation, early detection and immediate password rotation are critical. Run a free search at HEROIC.com today.
Breach Breakdown
112,523 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds