QLogs 300 PCS Jun 21, 2025: 15,176 US Records at the Series’ Minimum File Count
Smallest Batch, Strong Yield: QLogs 300 PCS Jun 21 Drops 15,176 US Records Without VIP
At just 300 stealer log files, the batch "QLogs 300 PCS 21-06-2025" represents the minimum file count observed across the entire QLogs 2025 dataset. Yet the per-file yield of approximately 50.59 records is well above the ~38-40 rec/file threshhold that would qualify a batch for VIP designation under the framework applied from June 26 onward. Released same-day on June 21, 2025, this batch is part of the pre-VIP-label cluster spanning June 20-23 -- a period during which the operator distributed PCS batches without the tiering system that would be formalized days later. The 300-file format is itself unusual; most QLogs PCS releases use 500, 1,000, or 1,500 files as their base unit.
QLogs 300 PCS (June 21, 2025): Stealer Log Summary
- Records Exposed: 15,176
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: June 21, 2025
300 Files: A Minimum Tier Format
The 300-file batch size does not appear again in the observed QLogs 2025 dataset. The operator's standard PCS packaging tiers -- 500, 1,000, 1,500, and occasionally 2,000 files -- suggest that 300 was either a one-time minimum-tier test, or a remnant of an earlier naming system before the operator settled on 500 as the base unit. The fact that this batch was released on June 21, the second day of the pre-VIP-label PCS cluster, supports the reading that QLogs' distribution system was still being calibrated in the Jun 20-23 window. The following day's Jun 22 batch stepped up to 500 files, and Jun 23 to 1,000 files -- a potential scaling test in real time before the operator locked in standard packaging conventions.
Infostealer Credentials Remain High-Risk Regardless of Batch Size
At 15,176 records, this is one of the smaller batches in the QLogs series by total record count -- but infostealr-harvested plaintext passwords carry identical risk at any scale. Each of the 15,176 email-password pairs was captured directly from the browser credential store of a compromised US endpoint, requiring no cracking or post-processing before deployment in credential stuffing campaigns. The 300-file constraint caps total records but does not reduce per-credential risk. For the affected users, the absence of a VIP label on this batch is irrelevant -- their credentails are in threat actor hands regardless of how the operator chose to package them.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to check whether your email or password has appeared in stealer log datasets like this one. Plaintext credentials from infostealer captures are immediately usable -- there is no delay between dataset acquisition and first exploitation attempt. Run a search at HEROIC's breach scanner and update any matched passwords without delay.
Breach Breakdown
15,176 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds