QLogs VIP 2467 PCS: 34,503 US Credentials at 14 Records Per File — the Lowest Yield in the Series
14 Records Per File: QLogs VIP 2467 PCS Posts the Series' Lowest Yield by a Wide Margin
QLogs VIP 2467 PCS 12-07-2025 surfaced July 19, 2025 with 34,503 US stealer log credentials across 2,467 endpoint files. At ~14.0 records per file, this batch stands apart from every other release in the documented QLogs 2025 US series. The previous low was QLogs VIP 600 MIX at ~24.9 rec/file -- itself flagged as unusually sparse. VIP 2467 PCS is 44% lower than that. Something fundamentaly different happened during this batch's collection: either these endpoints were dramatically lighter in stored credentials, the infostealer malware ran for a shorter time, or the harvest methodology itself changed.
QLogs VIP 2467 PCS (July 2025): Stealer Log Summary
- Records Exposed: 34,503
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: July 19, 2025
Why 14 Records Per File? Analyzing an Unusual Yield Anomaly
At ~14 rec/file, this batch challenges any straightforward explanation. Several hypotheses emerge. First, the infection vector may have reached a demographic with minimal credential storage: infrequent internet users, elderly users, or machines used primarily for a single service. Second, the infostealer variant may have run briefly -- detected and removed before completing a full credential extraction, capturing only the most recently accessed URLs rather than the full browser credential vault. Third, this may represent a different type of endpoint entirely: perhaps public-access machines, shared workstations, or kiosks with minimal saved credentials per session. The 2,467-file count is the second-largest PCS batch in the series by file count (behind VIP 4450 PCS), which makes the low yield-per-file even more analytically striking -- many endpoints, but sparse credentials per machine.
2,467 Files at Low Yield: The Math Still Adds Up
Despite the low per-file yield, the absolute record count of 34,503 is not negligible. At scale, even 14 records per endpoint multiplied by 2,467 compromised machines produces a meaningful credential pool. The 7-day staging window (Jul 12 collection to Jul 19 leak) is shorter than many other batches but consistent with standard QLogs processing times. The VIP designation is surprizing given the sparse yield -- the operator may have applied it based on the large endpoint count rather than per-file credential quality, or the VIP label reflects something about the geographic or demographic targeting rather than pure yield metrics.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including stealer log batches like this QLogs VIP 2467 PCS release. Even at 14 records per compromised machine, 34,503 credentials is a real exposure pool. Check at HEROIC's breach scanner to see if your email appeared in this or any other data breach.
Breach Breakdown
34,503 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds