AuroraLogsTeam 616count: 44,037 US Records From 616 Infected Devices
71 Credentials Per Device: AuroraLogsTeam 616count's March 24 Release Analyzed
The AuroraLogsTeam 616count batch, released on March 24, 2025, exposed 44,037 US records from 616 infected devices. What distinguises this release within the AuroraLogsTeam March 2025 campaign is its credential density: at approximately 71 records per infected device, the 616count batch represents one of the highest per-device yields in the entire series -- alongside the 1611count batch released the following day. The signifacant inclussion of API host data in the dataset suggests that infected machines disproportionately belonged to developers, IT professionals, or SaaS-heavy business users with extensive cloud service credential stores.
AuroraLogsTeam 616count (March 2025): Breach Summary
- Records Exposed: 44,037
- Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
- Breach Type: Stealer log
- Device Count (PCS): 616 infected devices
- Password Type: Plaintext -- directly usable with no cracking required
- Country: United States
- Date Leaked: March 24, 2025
API Host Data and Developer Credential Risk in the 616count Dataset
The presence of API host data in the 616count dataset marks this batch as particularly dangerous for organizations rather than just individual users. API host data captures the hostnames and service endpoints that infected devices were actively authenticated against at the time of infostealer compromise. This category of credential includes API keys, OAuth tokens, service account passwords, and other machine-to-machine authentication data stored in browser profiles or developer tools. When this data is extracted from developer machines or corporate workstations, it can provide direct access to cloud infrastructure, CI/CD pipelines, SaaS platforms, and internal business tools -- well beyond the consumer account takeover risk posed by standard email/password pairs.
March 24: The Day Before the Campaign Peak
The March 24 release of 616count served as the immediate precursor to the March 25 dual-batch release that would define AuroraLogsTeam's campaign peak. Released one day before the simultaneous 1611count (112,523 records) and 1021count (52,116 records) drops, the 616count batch established a steady release cadence leading into the campaign's largest day. This chronological context matters for incident response teams: organizations that were unaware of AuroraLogsTeam's activity on March 24 had less than 24 hours before the substantially larger March 25 drops arrived. The 616count release was a signal, not a standalone event, within the broader campaign timeline.
High Density Devices as Priority Targets for Credential Stuffing
With 71 credentials per device, the machines in the 616count batch were premium targets. Credential stuffing tools and account checker services prioritize datasets with high per-record density because each compromised device yields more actionable login attempts. A single device with 71 credentials represents 71 potential account takeovers across 71 distinct services -- from banking and email to enterprise platforms and e-commerce accounts. When multiplied across 616 devices, the 616count batch provided attackers with 44,037 ready-to-use credential pairs, each paired with the specific endpoint URL the credential was associated with at time of theft.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to check whether your email or credentials appear in the AuroraLogsTeam 616count release or any related stealer log. With 44,037 plaintext US credentials in active circulation since March 2025, timely detection is essential. Run a free search at HEROIC.com to see your exposure status.
Breach Breakdown
44,037 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds