The PUBx Stealer Log Gave Hackers 18,672 Passwords to Work With
What HEROIC Analysts Found in the PUBx Stealer Log
HEROIC analysts confirmed a verified data exposure tied to a stealer log file uploaded to a public Telegram channel on October 27, 2023, identified as "PUBx." The file contained 18,672 records harvested from compromised devices, each entry pairing an email address with a plaintext password and the URL of the service where those credentials were used. This data was not tucked away on a private dark web forum. It was broadcast on Telegram, meaning anyone subscribed to that channel could download the full list the moment it was posted. The window for damage opened in October 2023 and has not closed.
Why the PUBx Log Gave Attackers Everything They Need
Most stolen password data requires some level of technical effort before it can be used: hashes need to be cracked, encrypted files need keys. The PUBx log required none of that. The passwords were stored in plaintext, meaning an attacker could open the file and start testing credentials against live login pages within minutes. With 18,672 email and password pairs at their disposal, attackers don't need to target any one person specifically. They run automated tools that cycle through the entire list against popular sites like Gmail, Amazon, PayPal, or banking portals, looking for any combination that still works. Even a 1 percent success rate from this file translates to nearly 200 compromised accounts.
What Was Exposed in the PUBx Log
- Email addresses
- Plaintext passwords (readable immediately, no cracking needed)
- URLs and service endpoints associated with the compromised accounts
Why This Matters: Account Takeover Starts With One Password
The most dangerous thing about plaintext password leaks is the chain reaction they can trigger. Most people reuse passwords across multiple accounts, so a single exposed password can unlock email, social media, online banking, and work systems all at once. Once an attacker is inside an email account, they can request password resets for every other service linked to that address. What starts as a stolen credential from a browser on one device can snowball into identity theft, unauthorised purchases, and in some cases, access to a victim's employer's internal systems. The PUBx log provided the starting point for exactly that kind of cascading compromise for up to 18,672 people.
How Stealer Log Infections Happen
Stealer logs come from malware installed on a person's computer or phone, usually without any visible sign that anything is wrong. The infection most often arrives through a phishy email attachment, a cracked software download, or a malicious ad that runs code in the background. Once installed, the malware monitors what the user types and what their browser autofills, capturing credentials as they are entered. It also records the URL of every site where a credential is used, which is why each PUBx record includes a URL alongside the email and password. After collecting data from potentially hundreds of infected devices, the attacker bundles everything into a log file and distributes it, in this case on Telegram, to other criminals who can then exploit the credentials themselves.
Check If Your Accounts Were Exposed in the PUBx Breach
HEROIC's free breach scanner searches across more than 400 billion exposed records, including stealer log collections like PUBx. Enter your email address to find out if your credentials appeared in this leak or any other known breach. If your data shows up, change affected passwords immediately and enable two-factor authentication on every account you can. The scan is free, takes a few seconds, and could save you from a very costly surprize.
Breach Breakdown
18,672 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds