Breach Intelligence Report 26 Sep 2025

QLogs_Offical 1005 PCS May 21, 2025: 27,250 US Credentials in Sub-24-Hour Stealer Drop

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 27,250
Source Type Stealer log
Origin Telegram
Password Type plaintext

One Day From Harvest to Leak: The QLogs_Offical 1005 PCS Speed Drop

Before the QLogs operator standardized its name and tiering system, the batches went out under a slightly different banner: "QLogs_Offical" -- note the absent 'i' in "Official." The May 21, 2025 PCS batch is a textbook example of this early phase. Collected on May 21 and leaked on May 22, the turnaround was less than 24 hours. The 1,005 files -- an irregular count that would later give way to round numbers like 1,000 or 1,500 -- yielded 27,250 US credentials at roughly 27.1 records per file. Fast, rough, and still forming its identity as an operation.


QLogs_Offical 1005 PCS (May 2025): Stealer Log Summary

  • Records Exposed: 27,250
  • Data Types: Email addresses, plaintext passwords, URLs
  • Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
  • Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
  • Country: United States
  • Date Leaked: May 22, 2025

The "Offical" Typo: A Branding Artifact of the Early Series

Throughout May 2025, QLogs batches were consistently labeled "QLogs_Offical" rather than the corrected "QLogs" or "QLogs_Official." This is not a one-off error but a persistent early naming convention, appearing across multiple batches during this period. The typo signals an operator who hadn't yet standardized their branding or release workflow. By June 2025, the "Offical" variant had disappeared entirely, replaced by the cleaner "QLogs" prefix. The name shift tracks precisely with other signs of operational maturation: the introduction of round file counts, the VIP tiering system, and increasingly consistent per-file yields.


1,005 Files: What Irregular Counts Reveal

Standard QLogs batches in later months arrive in clean increments: 300, 500, 1,000, 1,500, 2,000, 2,500. The 1,005-file count in this May 21 batch doesn't fit that pattern. Neither does the 485 or 750 seen in other early-series releases. These irregular counts suggest the operator was packaging whatever the infostealer network delivered rather than curating to a predetermined file threshold. Later, the shift to round numbers reflects deliberate quality control -- either filtering files below a records-per-file threshold or structuring harvests to hit target sizes before packaging. The 1,005 count is an artifact of that pre-standardization period.


~27.1 Records Per File: Low Yield, High Velocity

At approximately 27.11 records per file, this batch sits below the yields typically associated with quality PCS harvests. The tradeoff is speed -- a sub-24-hour pipeline from collection to leak is extremley aggressive, leaving little time for filtering low-yield endpoints or quality-checking the output. For credentials defenders, this batch's lower per-file yield doesn't reduce the risk: each record still represents plaintext credentials extracted directly from a compromised US consumer endpoint, usable immediately for credential stuffing without any additional processing.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records -- including early QLogs_Offical batches from May 2025. If your credentials were captured in a batch like this one, a scan at HEROIC's breach scanner will surface the exposure before it's weaponized against you.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 26 Sep 2025
Check in 5 seconds

27,250 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #7,653 by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $197.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance