The BananaLogs 345count Leak Exposed 12,199 US Accounts in a 2023 Telegram Dump
HEROIC analysts uncovered a stealer log file uploaded to a public Telegram channel on November 4, 2023, under the name "BananaLogs 345count." The file represented 345 bundled log packages containing a combined 12,199 compromised records. Each record was harvested by infostealer malware from an infected device, capturing an email address, a plaintext password, and the URL of the service that credential belonged to. With 12,199 affected accounts, this is one of the larger single-upload stealer log incidents in this period, and the data remains a live threat to anyone whose credentials were included.
Why This Is Dangerous
BananaLogs 345count contains over 12,000 ready-to-use login packages. Because every password in the file is in plaintext, attackers need no decryption tools -- they can begin attempting logins on the exposed URLs immediately after downloading the file. From there, gaining access to an email account opens the door to password resets across banking apps, social media, e-commerce platforms, and cloud services. The scale of this breach means criminals have a large pool of accounts to work through, increasing the odds that many of these credentials are still active and unprotected. Every day that passes without a password change is another day an attacker can exploit this data.
What Was Exposed
- Email addresses
- Plaintext passwords
- Service URLs (the specific sites the stolen credentials unlock)
Why This Matters
A stealer log of this size provides significant fuel for credential stuffing operations. Automated tools can cycle through all 12,199 records across hundreds of websites in a short time, identifying which accounts are still active and which passwords have been reused elsewhere. Victims face risks ranging from unauthorized purchases and drained bank accounts to identity theft and social engineering attacks on their contacts. The data from stealer logs like BananaLogs 345count does not expire -- it gets traded and resold on dark web forums indefinitely, so the window of risk does not dissapear after the initial upload.
How Stealer Log Breaches Work
Stealer logs are produced by infostealer malware installed on victims' devices. The malware typically arrives through a phishing link, a fake software download, or a malicious browser extension. Once active, it silently harvests saved passwords from browsers and applications, recording the URL associated with each credential. Everything is packaged into a structured log file and sent back to the attacker, who then shares or sells the logs in bulk on platforms like Telegram. The victim rarely recieves any warning. This type of attack is entirely seperate from a company being hacked -- the malware targets individual users' computers directly, making it harder to detect and harder to contain. By the time a stealer log surfaces publicly, the infections that produced it have often been active for weeks.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion exposed records, including stealer logs like BananaLogs 345count, to check whether your email address has been compromised. If your data is found, you will recieve an instant alert with guidance on what to change and how to protect your accounts. Visit HEROIC.com to run your free scan in under 30 seconds -- no account required.
Breach Breakdown
12,199 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds