Breach Intelligence Report 26 Sep 2025

QLogs 300 PCS Jun 21, 2025: 15,176 US Records at the Series’ Minimum File Count

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 15,176
Source Type Stealer log
Origin Telegram
Password Type plaintext

Smallest Batch, Strong Yield: QLogs 300 PCS Jun 21 Drops 15,176 US Records Without VIP

At just 300 stealer log files, the batch "QLogs 300 PCS 21-06-2025" represents the minimum file count observed across the entire QLogs 2025 dataset. Yet the per-file yield of approximately 50.59 records is well above the ~38-40 rec/file threshhold that would qualify a batch for VIP designation under the framework applied from June 26 onward. Released same-day on June 21, 2025, this batch is part of the pre-VIP-label cluster spanning June 20-23 -- a period during which the operator distributed PCS batches without the tiering system that would be formalized days later. The 300-file format is itself unusual; most QLogs PCS releases use 500, 1,000, or 1,500 files as their base unit.


QLogs 300 PCS (June 21, 2025): Stealer Log Summary

  • Records Exposed: 15,176
  • Data Types: Email addresses, plaintext passwords, URLs
  • Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
  • Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
  • Country: United States
  • Date Leaked: June 21, 2025

300 Files: A Minimum Tier Format

The 300-file batch size does not appear again in the observed QLogs 2025 dataset. The operator's standard PCS packaging tiers -- 500, 1,000, 1,500, and occasionally 2,000 files -- suggest that 300 was either a one-time minimum-tier test, or a remnant of an earlier naming system before the operator settled on 500 as the base unit. The fact that this batch was released on June 21, the second day of the pre-VIP-label PCS cluster, supports the reading that QLogs' distribution system was still being calibrated in the Jun 20-23 window. The following day's Jun 22 batch stepped up to 500 files, and Jun 23 to 1,000 files -- a potential scaling test in real time before the operator locked in standard packaging conventions.


Infostealer Credentials Remain High-Risk Regardless of Batch Size

At 15,176 records, this is one of the smaller batches in the QLogs series by total record count -- but infostealr-harvested plaintext passwords carry identical risk at any scale. Each of the 15,176 email-password pairs was captured directly from the browser credential store of a compromised US endpoint, requiring no cracking or post-processing before deployment in credential stuffing campaigns. The 300-file constraint caps total records but does not reduce per-credential risk. For the affected users, the absence of a VIP label on this batch is irrelevant -- their credentails are in threat actor hands regardless of how the operator chose to package them.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to check whether your email or password has appeared in stealer log datasets like this one. Plaintext credentials from infostealer captures are immediately usable -- there is no delay between dataset acquisition and first exploitation attempt. Run a search at HEROIC's breach scanner and update any matched passwords without delay.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 26 Sep 2025
Check in 5 seconds

15,176 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,212 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $109.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance