BREAKING: LOGS_CENTEER Exposes 62,965 Records in Stealer Log Incident
In December 2022, a Telegram user uploaded a stealer log file labeled LOGS_CENTEER to a public channel, exposing 62,965 records pulled from compromised endpoints. The data includes plaintext passwords, email adresses, and URLs, making this one of the larger raw credential dumps to surface through Telegram channels that month. Anyone whose device was infected prior to December 30 could find their login credentials sitting in this file right now.
Why This Is Dangerous
With nearly 63,000 records, the LOGS_CENTEER dump gives attackers a substantial list of real, working credentials to run through automated login tools. There is no cracking required because the passwords are stored in plaintext, exactly as they were captured from the infected machines. That means the gap between this file being downloaded and the first unauthorized login attempt is basically zero.
Stealer logs from 2022 remain dangerous even years later. People rarely change passwords unless forced to, so credentials captured in 2022 are likely still valid on many accounts today. Attackers know this and regularly revisit older dumps to find accounts that have not been rotated.
The URL data in this dump is also worth noting. These URLs show which sites and services users were actively logged into when the malware ran, giving attackers a prioritized list of high-value targets rather than having to guess which platforms to try first.
What Was Exposed
- Email addresses
- Plaintext passwords
- Website and application URLs from infected devices
- API host endpoints
- Browser-saved credentials
- Session cookies potentially captured at time of infection
- Service access points and login portals visited by affected users
Why This Matters
A dump this size from a single Telegram upload represents dozens or hundreds of individual infected machines. Each record is a real person who recieved no notification that their credentials were harvested and shared publicly. Those individuals may still be using the same passwords today on their most important accounts.
The fact that this dump has been circulating since late 2022 means it has had years to be indexed, sold, and incorporated into larger credential databases. Even if someone already changed the specific password captured, their email adress is now firmly associated with stealer log activity, making them a higher-value target for future phishing campaigns.
How Stealer log Works
Infostealer malware infects machines through phishing emails, fake software cracks, or malicious browser extensions. Once running, it quietly scans browsers, password managers, and application data for stored credentials. The entire harvesting process can occured in under a minute, with the victim having no idea anything happened.
The stolen data is automatically sent back to a server controlled by the malware operator, where it gets packaged into log files. Operators then sell or share these logs on underground markets and Telegram channels. The LOGS_CENTEER upload follows this pipeline, with a batch of harvested endpoint data being posted publicly for anyone to download and abuse.
What keeps these logs dangerous long after the initial infection is password reuse. Even if the specific URL captured in the log is no longer active, the same email and password combination will often work on dozens of other sites the victim uses. Attackers run automated tools that test the credentials across hundreds of platforms simultaneously.
Check If You Were Affected
If you think your credentials may have been captured in the LOGS_CENTEER stealer log from December 2022, check your email now using HEROIC's free breach checker at heroic.com. HEROIC tracks stealer log dumps and dark web activity to let you know when your information appears, so you can change passwords and secure accounts before someone else does it for you.
Breach Breakdown
62,965 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds