LeakBase Algeria by Gostingr: 48,336 Stolen Records Exposed
In June 2024, HEROIC analysts identified a stealer log published on a prominent cybercrime forum, attributed to the threat actor known as Gostingr under the label "LeakBase Algeria logs." The log exposed 48,336 records harvested by infostealer malware from infected user devices. What makes this breach particularly dangerous is the inclusion of plaintext passwords alongside email addresses, usernames, IP addresses, credit card data, and homepage URLs. This is not a company database breach -- it is the direct output of malware silently running on victims' computers, capturing credentials as they are typed or stored in browsers.
Why This Is Dangerous
Stealer logs represent one of the most severe categories of data exposure because the credentials are harvested in real time from live user sessions. Plaintext passwords mean there is no hashing barrier between the attacker and immediate account access. The inclusion of credit card data and homepage URLs provides attackers with financial targets and a roadmap to the exact online accounts the victim uses. These logs are typically sold or shared rapidly across criminal networks, exponentially increasing the number of threat actors who can exploit the data.
What Was Exposed
- Email Address
- Username
- IP Address
- Credit Card
- Plaintext Password
- HomePage URL
Why This Matters
Plaintext passwords give attackers instant access to any account where the victim reused that password, enabling large-scale credential stuffing and account takeover (ATO) attacks across email, banking, and social media platforms. Credit card data enables direct financial fraud. IP addresses can be used to identify the victim's approximate location and target network entry points. The combination of these data types creates a comprehensive attack profile that supports identity theft, financial fraud, and further malware distribution using the victim's own accounts.
How Stealer Logs Work
A stealer log is the output of infostealer malware -- malicious software installed on a victim's device, usually through a phishing email, malicious download, or compromised software installer. Once active, the malware silently harvests credentials saved in browsers, cookies, autofill data, and system information including IP addresses. It captures keystrokes during login sessions to collect credentials in plaintext. The harvested data is packaged into logs and transmitted to the attacker's command-and-control server, then sold or published on dark web forums and leak sites. Victims typically have no indication their device has been compromised until their accounts are taken over or fraudulent charges appear.
Check If You Are Affected
HEROIC's free breach scanner checks your email address against a database of over 400 billion compromised records, including data from stealer log incidents like this LeakBase Algeria logs breach. If your credentials were captured by infostealer malware, an immediate alert will guide you through securing your accounts. Run a free scan at heroic.com to find out if you have been compromised.
Breach Breakdown
48,336 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds