Search Your Email: The CRYPTONLOGS x985 Dump Exposed 14,254 Accounts
HEROIC analysts identified a stealer log labeled "12.12 CRYPTONLOGS x985" uploaded to a Telegram channel on December 24, 2022. The file contained 14,254 records, each pairing an email address with a plaintext password and a related API host URL. That volume and structure points to a large infostealer malware operation that harvested credentials from many infected devices before the log was packaged and shared.
Why the CRYPTONLOGS x985 Dump Is Dangerous
Over 14,000 complete login records were exposed with the passwords sitting in plaintext, so an attacker does not need to crack or guess anything to use them. Because each record also includes the URL the credentials belonged to, an attacker can move straight from the log to a working login. A dataset this size is valuable enough to be resold or redistributed further across dark web marketplaces and other Telegram channels, even years after it first surfaced.
What Was Exposed in the CRYPTONLOGS x985 Dump
- Email addresses
- Plaintext passwords
- Associated API host URLs
In total, 14,254 records were included in the file.
Why This Matters
A log of this size is exactly the kind of data used in credential stuffing campaigns, where stolen email and password pairs are tested automatically across thousands of other sites. Because each record here already ties a password to the service it opened, it also speeds up account takeover for anyone who reused that password elsewhere. That exposure can extend to email accounts, financial services, and raise the risk of identity theft.
How a Dump Like CRYPTONLOGS x985 Gets Built
Infostealer malware infects a device and quietly copies saved browser passwords, autofill data, and the API endpoints tied to them before sending everything back to whoever controls the malware. A log of over 14,000 records suggests credentials were gathered from many infected machines before being compiled and shared under a name like CRYPTONLOGS. These consolidated logs are routinely traded or resold in underground Telegram channels, which is how a single infostealer campaign can turn into a widely circulated dataset.
Search Your Email to Check If You Are Affected
With more than 14,000 accounts in this single dump, there is a real chance your email address is part of it. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including stealer logs like this one, so you can see what has been exposed and change any reused passwords before someone else does.
Breach Breakdown
14,254 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds