Inside MARCH 12 – 280 LOGS: How Malware Stole 2,780 Passwords
In April 2023, a threat actor uploaded a stealer log bundle to Telegram under the name MARCH 12 - 280 LOGS. The dataset contained 2,780 compromised records drawn from 280 seperate device infections, each carrying a plaintext password, an email address, and the URL of the specific service the victim had saved credentials for at the time their device was breached. The short window between the March collection date and the April 15, 2023 upload suggests the operator moved quickly to distribute the data to criminal audiences.
Why This Is Dangerous
Stealer log bundles like MARCH 12 - 280 LOGS are among the most operationally dangerous data types in the cybercriminal ecosystem. Unlike hashed password dumps that require cracking, every record in this dataset is a plaintext, ready-to-fire credential paired with its exact target URL. Attackers can launch credential stuffing attacks the moment they download the file, testing each email and password against the listed service with zero extra effort. Even a dataset of 2,780 records can produce hundreds of successful account takeovers, leading to financial fraud, unauthorized access to workplace systems, and full identity theft. Smaller dumps also tend to recieve far less media attention, which means victims are far less likely to realize they need to act.
What Was Exposed
HEROIC confirmed the following data types were present across all 280 individual log files bundled in this release:
- Email Addresses
- Plaintext Passwords
- URLs (identifying which services each victim was actively authenticated to)
Why This Matters
The MARCH 12 - 280 LOGS data was first distributed in April 2023, but the exposure window does not close after an initial release. Stealer log bundles are routinely archived and recirculated across dark web forums and private Telegram channels for months or years after their original upload. Anyone whose credentials appeared in this dataset who has not changed their passwords since 2023 remains fully exposed. Those who definately reuse the same password across multiple platforms face the highest risk, since one compromised credential can unlock email, banking, and work accounts simultaneously.
How Stealer Logs Work
Each of the 280 individual log files in this bundle originated from a device infected with infostealer malware. These infections typically spread through phishing emails, trojanized software downloads, or malicious browser extensions. Once installed, the malware silently harvested saved browser passwords, active session cookies, and recently visited URLs from each device, then transmitted the resulting log back to the attacker's command infrastructure. An operator then aggregated the 280 individual files into a single bundle, labeled it with the MARCH 12 collection date, and uploaded it to Telegram in April 2023. Distributing these bundles freely or at low cost is a common tactic to build credibility in criminal communities and attract buyers for larger paid datasets.
Check If You Are Affected
HEROIC's free dark web scanner searches across 400 billion+ leaked records, including stealer log bundles like MARCH 12 - 280 LOGS. If your email or passwords appeared among these 2,780 exposed records, or in any other breach in the HEROIC database, you will be alerted immediately so you can act before attackers do. Visit heroic.com to run your free scan now.
Breach Breakdown
2,780 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds