The LOGS_CENTER Telegram Leak Gave Attackers 24,019 Plaintext Passwords to Use Immediately
On October 17, 2023, a stealer log file labeled LOGS_CENTER was uploaded to a public Telegram channel by an anonymous user. Researchers monitoring the channel identified the file shortly after it appeared, and what they found was straightforward and alarming: 24,019 records containing email addresses, plaintext passwords, and URLs collected from compromised endpoints across the United States. There was no encryption, no obfuscation, and no barrier to entry. Anyone who downloaded the file had everything they needed to begin attacking accounts immediately.
Why This Is Dangerous
With 24,019 plaintext passwords in hand, an attacker does not need to be sophisticated. They can run the credentials through automated tools that test logins across hundreds of websites simultaneously. Email and social media accounts fall first. Then banking portals, payroll systems, and corporate VPNs. Because the log also includes URLs tied to each credential, attackers know exactly which services each victim uses, allowing them to skip the guesswork and go straight to high-value targets. Accounts compromised this way are often sold on dark web markets or used to pivot into larger corporate networks, where a single employee credential can open the door to sensitive company data.
What Was Exposed in the LOGS_CENTER Stealer Log
- Email addresses
- Plaintext passwords
- URLs (associated service endpoints)
- Endpoint and API host data
Why This Matters
Plaintext passwords eliminate every technical barrier between an attacker and your accounts. There is no hash to crack, no algorithm to reverse. If you used the same password on multiple services -- and most people do -- every one of those accounts is now at risk. The URLs included in this log make it even worse, because they tell attackers exactly which platforms to target with each set of credentials. The combination of email plus password plus service URL is sometimes called a "fullz" by criminals, and it is the most actionable form of stolen credential data. This breach is a textbook example of why password reuse is one of the most dangerous habits in digital life.
How Stealer Logs Work
Stealer logs are produced by infostealer malware that infects a victim's device and silently harvests credentials. The malware typically arrives through a phishing link, a fake software installer, or a malicious browser extension. Once running, it reads saved passwords from browsers like Chrome and Firefox, captures keystrokes, and collects session cookies. All of this data is bundled into a log file and transmitted back to the attacker. The infected device may show no signs of compromise. The malware is often designed to self-delete after the log is sent, leaving no trace. The resulting log files are then sold or distributed freely on platforms like Telegram, where they attract other criminals who use them for credential stuffing, account takeovers, and fraud. This cycle occured thousands of times in 2023 alone, and continues at scale today.
Check If You Are Affected
If your email address or any account credentials appear in the LOGS_CENTER log, you need to act before someone else does. HEROIC's free breach scanner checks against a database of over 400 billion compromised records, including stealer logs distributed on Telegram and other dark web channels. A scan takes under a minute. Visit HEROIC.com to find out if your data was exposed in this breach or any of the thousands of others in the DarkHive database.
Breach Breakdown
24,019 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds