Breach Intelligence Report 24 Apr 2026

Inside the EpilepsyLogsOwner Stealer Log: 16,659 US Accounts Exposed

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs EpilepsyLogsOwner 335count uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 16,659
Source Type Stealer log
Origin United States
Password Type plaintext

In July 2025, a Telegram user uploaded a stealer log containing 16,659 records tied to United States-based victims. The file, attributed to EpilepsyLogsOwner 335count, exposed email addresses, plaintext passwords, and the exact URLs where those credentials were used. This dataset circulated rapidly among cybercriminals the moment it was posted.


Why This Is Dangerous

Stealer logs are not abstract data breaches. Every record in this file represents a real person whose login credentials were silently harvested from their own device. With 16,659 plaintext passwords now in criminal hands, the attack surface is immediate and broad. Threat actors do not wait -- they run automated credential-stuffing tools within hours of a log being published. US-based accounts are among the most targeted because they are frequently linked to financial services, healthcare portals, and e-commerce platforms with high monetary value. The presence of service URLs in this dataset means attackers knew exactly which platforms to target first, eliminating the need for any guesswork on their part.


What Was Exposed

  • Email addresses (used as primary account identifiers across services)
  • Plaintext passwords (no decryption required -- ready for immediate use)
  • URLs (revealing which specific platforms and services were compromised)

Why This Matters

Password reuse is the force multiplyier that turns a single stealer log into a widespread breach. If any victim in this dataset used the same password across multiple platforms, each of those accounts is now at risk -- not just the one captured by the malware. US accounts tied to banking apps, payroll systems, or healthcare portals face the greatest downstream exposure. Infostealer logs like EpilepsyLogsOwner 335count are also aggregated into larger compilations and resold repeatedly on dark web marketplaces, meaning the danger does not expire when the original Telegram post disappears. Victims remain at risk indefinately.


How Stealer Log Breaches Work

Infostealer malware spreads through phishing emails, trojanized software downloads, malicious browser extensions, and fake cracked application installers. Once executed on a victim's device, it operates invisibly in the background. It captures every credential saved in the browser, every password typed into a login form, and every URL the victim visits. This data is structured into a log file and transmitted to an attacker-controlled server. The operator then packages the logs -- sometimes by geography, sometimes by volume -- and distributes them on Telegram channels or dark web forums. The EpilepsyLogsOwner naming convention suggests this was one collection among many maintained by the same threat actor.


Check If You Are Affected

HEROIC's free breach scanner searches across more than 400 billion exposed records, including stealer logs like EpilepsyLogsOwner 335count. Enter your email address and get instant results. If your credentials appeared in this breach or any related dataset, you will know immediatelly so you can change your passwords and secure your accounts before attackers act.

Breach Breakdown

Domain EpilepsyLogsOwner 335count uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 24 Apr 2026
Check in 5 seconds

16,659 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,797 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $120.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance