One Telegram Upload. 17,738 Records. The LOGS_CENTER 5 Stealer Log Exposed Thousands.
HEROIC analysts flagged the LOGS_CENTER 5 stealer log file on July 5th, 2023, after an anonymous user uploaded it to a public Telegram channel. The dataset contained 17,738 records harvested from compromised endpoints, covering email addresses, plaintext passwords, and URLs pointing to login pages and API services. The data was collected silently from infected machines and packaged into a structured file before being distributed openly online.
Why This Is Dangerous
Every record in the LOGS_CENTER 5 dataset represents a real set of login credentials that an attacker can use immediately. Because the passwords are stored in plain text, there is nothing to crack or decode. The attacker simply takes an email and password pair and tries it on Amazon, Netflix, a bank login, or any other service the victim might use. With 17,738 records available on a public Telegram channel, this data spread quickly to anyone looking for credential lists. The included URLs also give attackers a map of exactly which services these users logged into, reducing guesswork even further.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (login pages and API hosts)
Why This Matters
When email addresses and plaintext passwords end up in the wild together, the consequences can spread far beyond the original point of compromise. Credential stuffing attacks let bad actors test stolen logins across dozens of platforms in seconds. Account takeover can lead to drained bank balances, stolen identities, and hijacked social media profiles. Even users who think they have nothing worth stealing often find their email accounts weaponized for spam or their personal infomation sold on dark web marketplaces.
How Stealer Logs Work
Stealer logs are created when infostealer malware successfully infects a device. The malware spreads through phishing emails, fake software downlods, malicious browser extensions, or cracked applications. Once active, it quietly scans the system for saved browser credentials, autofill data, active cookies, and anything typed by the user. All of this gets packaged into a log file and transmitted back to the attacker. The victim's device looks and behaves completely normally the entire time, making detection very difficult without security tools in place.
Check If You Are Affected
The LOGS_CENTER 5 leak is one of thousands of incidents tracked in HEROIC's breach database. Run a free scan with HEROIC's identity monitoring tool to check whether your email appears in this dataset or any of the 400 billion plus exposed records we monitor. It takes seconds to find out if your data has been compromised and what steps to take next.
Breach Breakdown
17,738 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds