Breach Intelligence Report 19 Sep 2025

AuroraLogsTeam 616count: 44,037 US Records From 616 Infected Devices

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 44,037
Source Type Stealer log
Origin Telegram
Password Type plaintext

71 Credentials Per Device: AuroraLogsTeam 616count's March 24 Release Analyzed

The AuroraLogsTeam 616count batch, released on March 24, 2025, exposed 44,037 US records from 616 infected devices. What distinguises this release within the AuroraLogsTeam March 2025 campaign is its credential density: at approximately 71 records per infected device, the 616count batch represents one of the highest per-device yields in the entire series -- alongside the 1611count batch released the following day. The signifacant inclussion of API host data in the dataset suggests that infected machines disproportionately belonged to developers, IT professionals, or SaaS-heavy business users with extensive cloud service credential stores.


AuroraLogsTeam 616count (March 2025): Breach Summary

  • Records Exposed: 44,037
  • Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
  • Breach Type: Stealer log
  • Device Count (PCS): 616 infected devices
  • Password Type: Plaintext -- directly usable with no cracking required
  • Country: United States
  • Date Leaked: March 24, 2025

API Host Data and Developer Credential Risk in the 616count Dataset

The presence of API host data in the 616count dataset marks this batch as particularly dangerous for organizations rather than just individual users. API host data captures the hostnames and service endpoints that infected devices were actively authenticated against at the time of infostealer compromise. This category of credential includes API keys, OAuth tokens, service account passwords, and other machine-to-machine authentication data stored in browser profiles or developer tools. When this data is extracted from developer machines or corporate workstations, it can provide direct access to cloud infrastructure, CI/CD pipelines, SaaS platforms, and internal business tools -- well beyond the consumer account takeover risk posed by standard email/password pairs.


March 24: The Day Before the Campaign Peak

The March 24 release of 616count served as the immediate precursor to the March 25 dual-batch release that would define AuroraLogsTeam's campaign peak. Released one day before the simultaneous 1611count (112,523 records) and 1021count (52,116 records) drops, the 616count batch established a steady release cadence leading into the campaign's largest day. This chronological context matters for incident response teams: organizations that were unaware of AuroraLogsTeam's activity on March 24 had less than 24 hours before the substantially larger March 25 drops arrived. The 616count release was a signal, not a standalone event, within the broader campaign timeline.


High Density Devices as Priority Targets for Credential Stuffing

With 71 credentials per device, the machines in the 616count batch were premium targets. Credential stuffing tools and account checker services prioritize datasets with high per-record density because each compromised device yields more actionable login attempts. A single device with 71 credentials represents 71 potential account takeovers across 71 distinct services -- from banking and email to enterprise platforms and e-commerce accounts. When multiplied across 616 devices, the 616count batch provided attackers with 44,037 ready-to-use credential pairs, each paired with the specific endpoint URL the credential was associated with at time of theft.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to check whether your email or credentials appear in the AuroraLogsTeam 616count release or any related stealer log. With 44,037 plaintext US credentials in active circulation since March 2025, timely detection is essential. Run a free search at HEROIC.com to see your exposure status.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 19 Sep 2025
Check in 5 seconds

44,037 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,538 scanned today
Breach Rank #5,981 by affected users
Impact Score
2
sensitivity + scale + recency
Est. Financial Impact $318.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance