HEROIC Discovers live.com.ptlogsfox Leak of 11,915 Login Records
HEROIC Discovers the "live.com.ptlogsfox" Stealer Log
While monitoring Telegram channels known for distributing stolen credentials, HEROIC analysts discovered a file named "live.com.ptlogsfox" on August 28, 2025. Investigating further, the file was found to contain 11,915 records, each pairing an email address with a plaintext password and the URL of the site the credentials were used on. The file's name references live.com, a legacy Microsoft email domain, alongside "ptlogsfox," likely indicating the credentials were harvested through Firefox browser sessions.
Why This Is Dangerous
Once uncovered, the contents of the file proved just as concerning as the name suggested: every password is stored in plaintext, meaning an attacker can use the data immediately without needing to crack or decode anything. Each of the 11,915 records provides a complete, ready-to-use login, and the apparent focus on Microsoft email accounts makes this especially risky, since email accounts are often the key to resetting passwords elsewhere.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs and endpoints tied to each login
Why This Matters
If an attacker gains access to someone's email account, they can often reset passwords for banking, shopping, and social media accounts linked to that address, turning a single leaked credential into a much larger problem. Combined with the common habit of reusing passwords across sites, a discovery like this one highlights how quickly credential stuffing and account takeover can follow from a single stealer log.
How Stealer Logs Work
Investigators note that stealer malware typically spreads through pirated downloads, cracked software, or malicious attachments, and once active, it quietly extracts saved passwords and browser session data, often specifically from Firefox in cases like this one. That data is compiled into a log file and delivered back to the attacker, usually through an automated Telegram bot. Files like "live.com.ptlogsfox" are frequently posted publicly to build a reputation before more curated data is sold privately.
Check If You Are Affected
Discoveries like this one are exactly why regularly checking your exposure matters. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including stealer logs like this one, so you can quickly confirm whether your credentials were part of this leak and take action to secure your accounts.
Breach Breakdown
11,915 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds