The EpilepsyLogsOwner Breach Happened in 2025. The Data Just Went Public.
The infection happened months ago. The devices were compromised silently, passwords were harvested without the victims ever knowing, and the data sat in the hands of a Telegram operator known as EpilepsyLogsOwner. Then on June 28, 2025, the logs went public. In a single upload, 91,327 records containing email adresses, plaintext passwords, and URLs were released into the Telegram underground, where they are now being downloaded, traded, and weaponized by credential stuffing operations around the world.
Why This Is Dangerous
The gap between when credentials are stolen and when they become publicly available is not a window of safety. It is a window of exclusive access during which the original attacker and their closest associates exploit the data before anyone else knows it exists. Once a log goes public on Telegram, that window closes and the threat becomes democratized. Any criminal with a Telegram account and an automated stuffing tool can now test these 91,327 email and password pairs against financial institutions, email providers, and corporate login portals. The fact that the passwords are in plaintext means no cracking is neccessary.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (site endpoints and API hosts captured at the time of infection)
Why This Matters
Ninety-one thousand records is not a small leak. This is one of the larger single-actor Telegram stealer log releases HEROIC has tracked, and the scale matters because it means the data is now being processed by multiple criminal groups simultaneously. Credential stuffing tools run in parallel across hundreds of platforms, so account takeover attempts happen fast. Victims who reuse passwords across services face compounding risk: a single stolen credential can unlock email, banking, shopping, and work accounts in a chain. The URLs in this dataset also reveal personal browsing patterns, making targeted phishing a secondary threat for anyone whose data appears in this dump. Seperate buyer groups specializing in different fraud types will continue to exploit this data for months.
How Stealer Log Breaches Work
Stealer logs are produced by infostealer malware deployed through phishing campaigns, fake software downloads, and malicious browser extensions. Once installed on a victim's device, the malware operates invisibly, harvesting every password saved in the browser, capturing session cookies, and logging each URL the victim visits. This data is packaged into log files and exfiltrated to the attacker's infrastructure. Operators like EpilepsyLogsOwner aggregate logs from multiple infected devices, bundle them into numbered batches, and distribute them through private Telegram channels. The 1997count designation in this dump's name suggests the batch contained logs from aproximately 1,997 individual infected endpoints, each contributing multiple credential sets to the final collection.
Check If You Are Affected
HEROIC's free breach scanner searches over 400 billion records, including stealer log collections like EpilepsyLogsOwner 1997count. If your email address appears in this dump, your passwords need to change today. Enter your email to get your free scan instantly and find out whether your credentials are already in circulation among the criminal networks that have downloaded this file.
Breach Breakdown
91,327 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds