The Logs_Center_New Telegram Leak Exposed 15,585 US Account Credentials
HEROIC analysts flagged the Logs_Center_New stealer log appearing on a public Telegram channel on June 9, 2025. The log, shared by the operator .boxed.pw, contained 15,585 records tied predominantly to US-based accounts. Each record included an email address, a plaintext password, and a homepage URL indicating which websites the affected user was actively visiting at the time their device was compromised. The public nature of the Telegram channel means this data was available to anyone with access to the link, not just organized criminal groups.
Why US Account Holders Are at Immediate Risk From the Logs_Center_New Dump
Stealer logs targeting US users are particularly valuable to cybercriminals because American accounts are commonly linked to high-limit credit cards, PayPal accounts, Amazon storefronts, and corporate email systems. The homepage URLs in this log give attackers a precise list of which platforms each victim uses regularly. Rather than guessing, a criminal can go directly to the services most likely to yield financial access or sensitive data. With plaintext passwords in hand, there is no technical barrier to entry. The attacker simply logs in.
What Was Exposed in the Logs_Center_New Telegram Breach
- Email addresses (account identifiers for US-based services)
- Plaintext passwords (usable immediately, no decryption needed)
- HomePage URLs (a roadmap of the victim's most active online accounts)
Why This Matters: How US Credentials Fuel Credential Stuffing and Identity Theft
The 15,585 credential pairs in this log are a ready-made toolkit for credential stuffing attacks. Criminals run these combos through automated tools that test them against major US platforms simultaneously, including banking apps, e-commerce sites, and workplace tools like Microsoft 365 and Google Workspace. A single successful login gives them access to saved payment methods, tax documents, healthcare records, and internal company files. Identity theft is the next logical step when an attacker controls your primary email address, since that inbox is the master key to every account linked to it. Americans also face the added risk that Social Security numbers and financial account details are sometimes recovarble from compromised email threads alone.
How the Logs_Center_New Stealer Log Was Built
The Logs_Center_New dump is not the result of a server hack. It is the compiled output of infostealer malware installed on real people's devices. Infostealer infections typically begin with a deceptive download, a phishing email, a fake game mod, a pirated application, or a browser extension that looks legitimate. Once running, the malware harvests every saved password, session cookie, and autofill value stored in the browser. All of this is bundled into a structured log file and transmitted back to the attacker. Operators like .boxed.pw aggregate these logs across many malware campaigns, label them with a channel name like Logs_Center_New, and distribute them on Telegram. The victims often have no idea their machine was infected at all, because the malware runs silently in the backgrond without any visible symptoms.
Check If Your US Account Was Exposed in the Logs_Center_New Leak
HEROIC's breach scanner checks your email address against more than 400 billion compromised records, covering stealer logs like Logs_Center_New and thousands of other data dumps from around the world. If your credentials appeared in this Telegram leak or any related breach, HEROIC will surface the results instantly. Run a free check now and take action before someone else uses your data.
Breach Breakdown
15,585 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds