joker_reborn’s 500-File February Drop: 6,900 U.S. Logins Published to Telegram
500 Files. 6,900 U.S. Accounts. One Telegram Drop.
The name joker_reborn is a handle, not a company. It belongs to a threat actor who operates a Telegram channel dedicated to distributing stealer log collections. On February 26, 2023, they released a batch labeled "500 FILES FEBUARY FAMILY," a archive of 500 individual log files that together contained 6,900 U.S. credential records. HEROIC's DarkHive analysts confirmed the dataset: email addresses, plaintext passwords, and the exact URLs where each credential was originally captured.
The "FAMILY" label in the file name is a naming convention used by some stealer log operators to indicate that logs were sourced from personal or household devices rather than corporate endpoints. Whether accurate or not, U.S. personal accounts carry significant value: banking portals, email accounts, subscription services, and healthcare portals are all frequenly accessed from home computers.
What's Inside the joker_reborn February Archive
Despite the 500-file structure, the underlying data format is consistent across the archive:
- Email Addresses: 6,900 U.S. accounts
- Plaintext Passwords: Full cleartext per record
- Target URLs: Login pages specific to each credential pair
The multi-file structure is a common way to distribute large stealer collections on Telegram without hitting file size limits. Each of the 500 files likely represents the output from one infected machine, making this archive the aggregated yield from 500 separate endpoint compromises. That's 500 different people's credentials, packaged and published.
Why "Free" Stealer Logs Are Dangerous
joker_reborn's public releases, like this one, are often offered at no cost on Telegram. Free distribution might seem less threatening than data sold on underground markets, but it's arguably worse for victims. A paid dataset has a limited buyer pool. A free public drop can be downloaded by thousands of people instantaneously. Every person who grabs this archive is a potential attacker against the 6,900 accounts inside it.
For the people in this file, the exposure chain is straighforward: their email and password are in cleartext, the target URL is included, and the data has been freely available since February 2023. Any account where that password was reused has been at risk for over two years.
HEROIC Indexed the joker_reborn Archive
The full joker_reborn February collection is part of HEROIC's breach database, which now covers more than 400 billion records. Their free scanner checks any email against this dataset instantly. If your credentials were in the 500-file drop or any related Telegram release, you'll see it in seconds.
Breach Breakdown
6,900 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds