Breach Intelligence Report 26 Sep 2025

QLogs Part 2 1000 PCS Jun 8, 2025: 55,619 US Credentials in a Split-Part Release

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 55,619
Source Type Stealer log
Origin Telegram
Password Type plaintext

Split Delivery: QLogs.part2 Carries 55,619 US Records as Half of a 2,000-File Jun 8 Package

On June 8, 2025, the QLogs operator deployed an unusual distribution format: instead of a single batch, they split a 2,000-file PCS harvest into two separate packages -- QLogs.part1 1000 PCS and QLogs.part2 1000 PCS -- each carrying approximately 1,000 stealer log files and released on the same day. The ".part2" batch carries 55,619 US credentails at approximately 55.62 records per file. Combined with the companion QLogs.part1 batch (60,482 records), the full Jun 8 harvest totals 116,101 US credentials across 2,000 files at a blended yield of approximately 58.05 rec/file. Neither part carries a VIP label, consistent with the pre-Jun-26 era where VIP had not yet been applied to PCS distribtion channels.


QLogs Part 2 1000 PCS (June 8, 2025): Stealer Log Summary

  • Records Exposed: 55,619
  • Data Types: Email addresses, plaintext passwords, URLs
  • Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
  • Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
  • Country: United States
  • Date Leaked: June 8, 2025

Why Split Into Two Parts?

The ".part1/.part2" naming convention does not reappear in the QLogs dataset after June 8. By late June, the operator was releasing 1,500-file batches as single packages in same-day format. The June 8 split may reflect a technical or platform constraint at that stage of the pipeline -- possibly a file size limit on the distribution channel, a batch-processing queue that handled 1,000 files at a time, or simply an earlier methodolgy that was replaced as the infrastructure matured. The combined 58.05 rec/file yield across the full 2,000-file package would comfortably qualify for VIP designation under the framework established 18 days later, further supporting the timeline that VIP labeling for PCS was introduced around June 26.


116,101 Combined Records: A Major Early-Series Output

Taken together, the Jun 8 QLogs.part1 and QLogs.part2 batches constitute one of the larger single-collection output events in the 2025 series: 116,101 US plaintext email-password pairs harvested from approximately 2,000 malware-infected endpoints on a single day. Infostealer credentials at this scale provide significant attack surface coverage -- a threat actor running credential stuffing tools against US financial and retail login portals with this corpus could generate thousands of successful account accesses before the affected users have any awareness of compromise. The plaintext nature of the passwords means the entire dataset is immediately operational upon acquisition.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to determine whether your email address or password has appeared in stealer log releases like the June 8 QLogs split package. Credentials in this batch have been in threat actor circulation since June 2025. Search your email at HEROIC's breach scanner and update any matched passwords before they're used against your accounts.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 26 Sep 2025
Check in 5 seconds

55,619 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #N/A by affected users
Impact Score
2
sensitivity + scale + recency
Est. Financial Impact $402.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance