Breach Intelligence Report 19 Sep 2025

AuroraLogsTeam 1611count: 112,523 US Records — The Largest Single Batch

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 112,523
Source Type Stealer log
Origin Telegram
Password Type plaintext

112,523 Records, 1,611 Devices: AuroraLogsTeam's Largest Single Release Analyzed

On March 25, 2025, AuroraLogsTeam released two batches in a single day. The 1611count batch and the 1021count batch arrived simutaneously, together exposing over 164,000 US records in 24 hours. The 1611count batch was the larger of the two -- and the largest individual release in the entire AuroraLogsTeam March 2025 campaign. With 112,523 records harvested from 1,611 infected devices, and an average credential density of approximately 70 records per device, this batch was remarkably dennse in comparison to other releases in the series. The impackt on affected users was immediate: every credential extracted was in plaintext, ready to use.


AuroraLogsTeam 1611count (March 2025): Breach Summary

  • Records Exposed: 112,523
  • Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
  • Breach Type: Stealer log
  • Device Count (PCS): 1,611 infected devices
  • Password Type: Plaintext -- directly usable with no cracking required
  • Country: United States
  • Date Leaked: March 25, 2025

Highest Credential Density in the Series: What 70 Records Per Device Means

A per-device credential density of approximately 70 records means the average infected machine in the 1611count batch had 70 sets of email/password pairs stored in its browser credential vaults. For context, the March 20 231count batch averaged about 49 credentials per device, and the March 21 281count batch averaged approximately 58. The 1611count batch's 70 per-device average suggests targeting of high-value, credential-dense machines -- likely active professionals or frequent online shoppers with extensive saved login libraries. Machines with dense credential stores are disproportionately valuable to threat actors executing credential stuffing campaigns at scale.


The March 25 Dual Release: 1611count and 1021count Together

The simultaneous release of 1611count and 1021count on March 25 was the single highest-volume day in AuroraLogsTeam's documented March 2025 activity. The combined total for the day was 164,639 records from 2,632 infected devices. This dual-drop pattern -- also seen on March 20 with the 726count and 231count batches -- suggests AuroraLogsTeam maintained multiple concurrent collection pipelines, aggregating results and releasing them in synchronized batches rather than a continuous stream. The March 25 dual release represented the operational peak of the campaign before the March 27 1595count release closed things out.


API Host Data and Enterprise Attack Surface

Among the data types included in the 1611count dataset is API host data -- records capturing the API endpoints and hostnames that infected devices had active credentials for at the time of compromise. This category of data extends the risk profile beyond individual consumer accounts. API credentials harvested from developer machines, corporate laptops, or SaaS-connected workstations can provide access to backend systems, CI/CD pipelines, cloud infrastructure, and business intelligence platforms. In a batch as large as 112,523 records, even a small percentage of API credentials represents a significant enterprise attack surface.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to help you identify whether your credentials appear in the AuroraLogsTeam 1611count release or any related stealer log operation. With 112,523 plaintext records in circulation, early detection and immediate password rotation are critical. Run a free search at HEROIC.com today.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 19 Sep 2025
Check in 5 seconds

112,523 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,039 scanned today
Breach Rank #3,737 by affected users
Impact Score
5
sensitivity + scale + recency
Est. Financial Impact $814.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance