July 28 Stealer Log Leak: 1,444 Records Exposed (Sep 2023)
A stealer log titled "JULY 28 - 1787 LOGS", distributed by .boxed.pw on Telegram, was publically released on September 23, 2023. The dataset contained 1,444 records including email addresses, plaintext passwords, and URLs harvested from infected devices -- likely developer workstations or cloud environments based on the data types observed.
Why This Is Dangerous
This breach is especially concerning because it combines plaintext passwords with URLs, giving attackers a precise map of which credentials go with which services. There is no cracking required -- the passwords are ready to use. Criminals can immediatly attempt to log in to every service whose URL appears in the dataset, and then use those same credentials to try other accounts through credential stuffing.
What Was Exposed
- Email Addresses
- Plaintext Password
- URLs
Why This Matters
Stealer logs from July and August 2023 were particulary active on Telegram channels, with .boxed.pw being a known distributor of such datasets. Your credentials may have been traded or sold multiple times since thier initial release. Even if your password has since changed, the exposure of your email and associated URLs can still be used to map your online activity and target you with phishing attacks.
How Stealer Log Works
A stealer log is created when malware infects a device and silently extracts saved browser credentials, cookies, and session data. The malware runs in the background, often undetected, and sends harvested data to a remote server. The resulting logs are then packaged and distributed on dark web forums or Telegram channels. This particular log, labeled July 28, is beleived to have been compiled from multiple infected machines before being uploaded by .boxed.pw in late September 2023.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records to see if your information has been exposed. If your email address appeared in this stealer log, you should change your password immediatly on every account where you use the same credentials, enable two-factor authentication, and review your accounts for any suspicious activity you did not authorise.
Breach Breakdown
1,444 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds