JUNE 7 – 4211 LOGS: 76,622 Records Exposed in September 2023
Three Batches, One Collection Day: The Scale of the JUNE 7 Series
JUNE 7 - 4211 LOGS is the second of three named batches from the JUNE 7 stealer log campaign, all releasing on September 26, 2023. Combined, the JUNE 7 series -- 4121 LOGS (86,386 records), 4211 LOGS (76,622 records), and 4100 LOGS (72,184 records) -- accounts for over 234,000 plaintext credentials from more than 12,000 compromised devices. All of it collected on June 7, 2023. All of it held for approximately 111 days before simultaneous release.
JUNE 7 - 4211 LOGS (September 2023): Breach Summary
- Records Exposed: 76,622
- Data Types: Usernames, plaintext passwords, endpoint URLs, API hosts
- Breach Type: Stealer log
- Date Leaked: September 26, 2023
The Scope of a Single-Day Collection Campaign
The "4211" in this batch name is a device count: 4,211 unique endpoints compromised on June 7, 2023. That's a significant single-day infection haul, suggesting either a large-scale phishing campaign, a compromised software distribution channel, or an automated malware deployment with broad geographic reach. At 76,622 records from 4,211 devices, the average yield is roughly 18 credentials per machine -- consistent across the JUNE 7 series, suggesting a uniform infection vector that hit similarly structured devices.
What does "uniform infection vector" mean practically? It means these 4,211 devices were likely compromised the same way, on the same day, through the same method. A single well-crafted phishing campaign, a poisoned software installer, or a compromized update mechanism could produce this kind of concentrated single-day haul. The operator then held the entire collection for 111 days before releasing three separate batches simultaneously into the September 26 clearing event.
Batch Segmentation and Release Strategy
Rather than releasing all 12,000+ devices as a single monolithic dump, the JUNE 7 operator segmented the haul into three named batches: 4121 LOGS, 4211 LOGS, and 4100 LOGS. This segmentation strategy is deliberate. Separate named releases are easier to distribute across different channels, harder for defenders to correlate into a single campaign, and allow the operator to reach different Telegram audiences simultaneously.
All three JUNE 7 batches hit Telegram on September 26, 2023 -- the same day. So the segmentation was about channel coverage and market fragmentation, not temporal separation. Each batch could be shared to a different Telegram channel, reaching different audiences while collectively swamping the underground market with over 234,000 credentials from a single June 7 collection campaign.
JUNE 7 - 4211 LOGS in the Broader September 26 Cluster
The September 26 cluster extended well beyond the JUNE 7 series. MAY-series batches, GODELESS CLOUD, Master cloud FREE LOGS, TOR_LOG BR, Usmancloud, and more all dropped in the same 48-hour window. The JUNE 7 series alone -- at 234,000+ records -- represents the largest individual contributor to that cluster by volume.
For potential victims, the practical implication is straitforward: credentials exposed in the September 26-27 clearing event have been in circulation for over two years. If an account was compromized in June 2023 and the credentials haven't been changed, that account remains at risk today.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including the full JUNE 7 series and thousands of other stealer batches. Run a free scan to find out if your email, username, or password has appeared in any known breach or leak.
Breach Breakdown
76,622 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds