QLogs Part 2 1000 PCS Jun 8, 2025: 55,619 US Credentials in a Split-Part Release
Split Delivery: QLogs.part2 Carries 55,619 US Records as Half of a 2,000-File Jun 8 Package
On June 8, 2025, the QLogs operator deployed an unusual distribution format: instead of a single batch, they split a 2,000-file PCS harvest into two separate packages -- QLogs.part1 1000 PCS and QLogs.part2 1000 PCS -- each carrying approximately 1,000 stealer log files and released on the same day. The ".part2" batch carries 55,619 US credentails at approximately 55.62 records per file. Combined with the companion QLogs.part1 batch (60,482 records), the full Jun 8 harvest totals 116,101 US credentials across 2,000 files at a blended yield of approximately 58.05 rec/file. Neither part carries a VIP label, consistent with the pre-Jun-26 era where VIP had not yet been applied to PCS distribtion channels.
QLogs Part 2 1000 PCS (June 8, 2025): Stealer Log Summary
- Records Exposed: 55,619
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: June 8, 2025
Why Split Into Two Parts?
The ".part1/.part2" naming convention does not reappear in the QLogs dataset after June 8. By late June, the operator was releasing 1,500-file batches as single packages in same-day format. The June 8 split may reflect a technical or platform constraint at that stage of the pipeline -- possibly a file size limit on the distribution channel, a batch-processing queue that handled 1,000 files at a time, or simply an earlier methodolgy that was replaced as the infrastructure matured. The combined 58.05 rec/file yield across the full 2,000-file package would comfortably qualify for VIP designation under the framework established 18 days later, further supporting the timeline that VIP labeling for PCS was introduced around June 26.
116,101 Combined Records: A Major Early-Series Output
Taken together, the Jun 8 QLogs.part1 and QLogs.part2 batches constitute one of the larger single-collection output events in the 2025 series: 116,101 US plaintext email-password pairs harvested from approximately 2,000 malware-infected endpoints on a single day. Infostealer credentials at this scale provide significant attack surface coverage -- a threat actor running credential stuffing tools against US financial and retail login portals with this corpus could generate thousands of successful account accesses before the affected users have any awareness of compromise. The plaintext nature of the passwords means the entire dataset is immediately operational upon acquisition.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address or password has appeared in stealer log releases like the June 8 QLogs split package. Credentials in this batch have been in threat actor circulation since June 2025. Search your email at HEROIC's breach scanner and update any matched passwords before they're used against your accounts.
Breach Breakdown
55,619 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds