QLogs_Offical 1005 PCS May 21, 2025: 27,250 US Credentials in Sub-24-Hour Stealer Drop
One Day From Harvest to Leak: The QLogs_Offical 1005 PCS Speed Drop
Before the QLogs operator standardized its name and tiering system, the batches went out under a slightly different banner: "QLogs_Offical" -- note the absent 'i' in "Official." The May 21, 2025 PCS batch is a textbook example of this early phase. Collected on May 21 and leaked on May 22, the turnaround was less than 24 hours. The 1,005 files -- an irregular count that would later give way to round numbers like 1,000 or 1,500 -- yielded 27,250 US credentials at roughly 27.1 records per file. Fast, rough, and still forming its identity as an operation.
QLogs_Offical 1005 PCS (May 2025): Stealer Log Summary
- Records Exposed: 27,250
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: May 22, 2025
The "Offical" Typo: A Branding Artifact of the Early Series
Throughout May 2025, QLogs batches were consistently labeled "QLogs_Offical" rather than the corrected "QLogs" or "QLogs_Official." This is not a one-off error but a persistent early naming convention, appearing across multiple batches during this period. The typo signals an operator who hadn't yet standardized their branding or release workflow. By June 2025, the "Offical" variant had disappeared entirely, replaced by the cleaner "QLogs" prefix. The name shift tracks precisely with other signs of operational maturation: the introduction of round file counts, the VIP tiering system, and increasingly consistent per-file yields.
1,005 Files: What Irregular Counts Reveal
Standard QLogs batches in later months arrive in clean increments: 300, 500, 1,000, 1,500, 2,000, 2,500. The 1,005-file count in this May 21 batch doesn't fit that pattern. Neither does the 485 or 750 seen in other early-series releases. These irregular counts suggest the operator was packaging whatever the infostealer network delivered rather than curating to a predetermined file threshold. Later, the shift to round numbers reflects deliberate quality control -- either filtering files below a records-per-file threshold or structuring harvests to hit target sizes before packaging. The 1,005 count is an artifact of that pre-standardization period.
~27.1 Records Per File: Low Yield, High Velocity
At approximately 27.11 records per file, this batch sits below the yields typically associated with quality PCS harvests. The tradeoff is speed -- a sub-24-hour pipeline from collection to leak is extremley aggressive, leaving little time for filtering low-yield endpoints or quality-checking the output. For credentials defenders, this batch's lower per-file yield doesn't reduce the risk: each record still represents plaintext credentials extracted directly from a compromised US consumer endpoint, usable immediately for credential stuffing without any additional processing.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including early QLogs_Offical batches from May 2025. If your credentials were captured in a batch like this one, a scan at HEROIC's breach scanner will surface the exposure before it's weaponized against you.
Breach Breakdown
27,250 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds