Breach Intelligence Report 26 Sep 2025

QLogs VIP 1070 MIX May 31, 2025: 50,584 US Credentials in an Early Series MIX Release

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 50,584
Source Type Stealer log
Origin Telegram
Password Type plaintext

An Early Benchmark: QLogs VIP 1070 MIX Surfaces May 31 Data in a Jun 10 Release

The batch "QLogs VIP 1070 MIX 31-05-2025" is one of the earliest releases in the observed QLogs 2025 dataset, carrying 50,584 US credentails collected as far back as May 31, 2025 and distributed ten days later on June 10. The VIP label confirms that the operator's premium tiering system was already in use for MIX batches well before the June 20-23 cluster of non-VIP PCS releases -- establishing that VIP was a MIX designation first, extended to the PCS format only around June 26. The irregular file count of 1,070 -- similar to the later 1,143-file anomaly in the VIP PCS series -- suggests the operator's MIX batches have always had some tolerance for non-round file counts, unlike the more standardized PCS packaging.


QLogs VIP 1070 MIX (May-June 2025): Stealer Log Summary

  • Records Exposed: 50,584
  • Data Types: Email addresses, plaintext passwords, URLs
  • Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
  • Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
  • Country: United States
  • Date Leaked: June 10, 2025

47.3 Rec/File: Above Average for MIX, Solidly Within VIP Range

At approximately 47.3 records per file, this batch exceeds the typical QLogs MIX yield of 24-41 rec/file while falling short of the ultra-high-yield MIX output seen in the June 12 VIP 2500 MIX batch at ~65.1 rec/file. The 47.3 figure places it comfortably in the VIP-eligible range for MIX batches, consistent with the operator's apparent criterion of applying the premium label when per-file output materially exceeds baseline. The irregulr 1,070 file count is consistent with the operator using MIX batches as a catch-all for residual or mixed endpoint pools -- assembled from whatever credentials remained after higher-priority packaging, resulting in non-round file counts that reflect actual available inventory rather than a standardized tier.


10-Day Staging: Textbook MIX Pipeline

The May 31 collection-to-June 10 release window is a 10-day staging period, falling precisely within the 9-13 day range observed for QLogs MIX batches throughout the 2025 dataset. This consistency -- from the 2,500-file VIP MIX at 12 days to this 1,070-file VIP MIX at 10 days -- confirms the MIX staging pipeline operates on a fixed schedule, likely involving automated deduplication, geographic tagging, and quality assessment before release. At this stage of the series, the infostealr pipeline had already achieved a level of operational regularity that would remain constant through at least the August-September batches observed later in the dataset.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records to check whether your email or password has appeared in stealer log datasets, including early-series MIX releases like this one. The May 31 collection date means this data has been in threat actor hands since at least June 2025 -- well ahead of most breach notification timelines. Search your email at HEROIC's breach scanner and update any matched passwords immediately.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 26 Sep 2025
Check in 5 seconds

50,584 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,224 scanned today
Breach Rank #N/A by affected users
Impact Score
2
sensitivity + scale + recency
Est. Financial Impact $366.0K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance