Breach Intelligence Report 19 Sep 2025

AuroraLogsTeam 678count: 38,480 US Records Exposed in April 2025 Stealer Log

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 38,480
Source Type Stealer log
Origin Telegram
Password Type plaintext

AuroraLogsTeam's April Push: The 678count Stealer Log

The AuroraLogsTeam campain, initially tracked through a concentrated March 2025 deployment of US-targeted stealer logs, did not end with March. On April 10, 2025, a new AuroraLogsTeam batch surfaced on Telegram -- 678 infescted devices yielding 38,480 records of email addresses, plaintext passwords, endpoint URLs, and API host data. This upload, recieved just four days before the separate AlphaFreeLogs campaign launched, represents a significant continuation of AuroraLogsTeam's operational pattern into April.


AuroraLogsTeam 678count (April 2025): Breach Summary

  • Records Exposed: 38,480
  • Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
  • Breach Type: Stealer log
  • Device Count (PCS): 678 infected devices
  • Password Type: Plaintext -- directly usable with no cracking required
  • Country: United States
  • Date Leaked: April 10, 2025

Credential Density: 57 Records Per Infected Device

The 678count batch yields approximately 57 credential records per infected device -- a density metric that falls in the mid-range for AuroraLogsTeam batches. This suggests devices with moderate browser credential store populations: users with active online presence across a moderate number of authenticated platforms, but not the power users seen in denser batches. Mid-density batches are particularly valuable for credential stuffing because they tend to contain a higher proportion of active, regularly-used credentials rather than the stale or test credentials sometimes found in very high-density dumps.

At 57 records per device, each compromised machine contributes a meaningful volume of actionable credentials -- email/banking/streaming/SaaS combinations that remain valid for immediate stuffing operations.


April Continuation: What It Means for the Campaign Timeline

The April 10 upload confirms that AuroraLogsTeam maintained operational cadence beyond its primary March 2025 deployment window. The campaign's March activity (March 17-27) was characterized by high-frequency uploads, sometimes multiple batches per day. The April continuation suggests a secondary distribution phase -- possibly drawing from the same pool of compromised endpoint data, or from fresh infections collected during April.

Crucially, this April 10 batch arrived just four days before the AlphaFreeLogs campaign launched on April 14, 2025. The overlap zone between these two campaigns creates a concentrated period of US-targeted stealer log activity that significantly amplified the overall credential exposure for American users during this period.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address appears in known data breaches, including stealer logs from the AuroraLogsTeam campaign. Run a free scan at HEROIC.com to identify any ongoing credential exposure.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 19 Sep 2025
Check in 5 seconds

38,480 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #6,415 by affected users
Impact Score
2
sensitivity + scale + recency
Est. Financial Impact $278.4K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance