QLogs_Offical530 MIX May 12, 2025: 21,009 US Credentials in 2-Day Stealer Log Drop
A Name Without a Space: The QLogs_Offical530 MIX and Its Naming Anomaly
Among the various naming quirks that define the early QLogs series, the "QLogs_Offical530 MIX" batch stands out for a structural reason: the file count "530" is merged directly into the operator name with no separating space -- "QLogs_Offical530" rather than "QLogs_Offical 530." It's a small detail, but in a series already marked by a persistent typo ("Offical" instead of "Official"), it suggests the early batches were labeled with limited consistency. The batch itself: 530 files, 21,009 US credentials, collected May 12 and leaked May 14 -- a 2-day turnaround -- alongside a companion 900 MIX batch from the identical collection date.
QLogs_Offical530 MIX (May 2025): Stealer Log Summary
- Records Exposed: 21,009
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: May 14, 2025
~39.6 Records Per File: Standard MIX Yield
At approximately 39.6 records per file, the QLogs_Offical530 MIX sits comfortably within the expected range for QLogs MIX batches from this period. MIX-tier harvests draw from heterogeneous endpoint pools -- no strict demographic or enterprise targeting -- which produces moderate yields compared to focused PCS collections. For context, the companion 900 MIX released on the same day from the same May 12 collection achieved ~48.6 rec/file, a noticeably higher density from a larger endpoint pool. The 530 batch's lower yield may reflect a different source segment or an earlier collection time within the May 12 window before higher-quality endpoints came online.
May 12 Dual MIX Release: The 530 and 900 Together
The QLogs_Offical530 and QLogs_Offical 900 MIX batches were both collected May 12 and released within one day of each other -- the 530 on May 14, the 900 on May 13. Together they represent 1,430 files and 64,744 US credential records from a single collection date. The back-to-back releases rather than simultaneous publication suggests the operator processed and packaged the two batches independantly, possibly clearing the smaller one first. This paired-release pattern would reappear in the QLogs series -- most notably with the May 13 dual PCS collection -- pointing to an operator who regularly harvested in multiple concurrent batch streams.
2-Day Staging in Mid-May 2025
A two-day gap between collection and release puts the QLogs_Offical530 MIX in the accelerated end of the mid-May staging spectrum. April batches took weeks; by late May, the operator would be pushing batches same-day. The 2-day window here is consistent with an operation that had streamlined its distribution pipeline enough to move quickly but still maintained a brief review or upload delay. For the 21,009 victims in this batch, that 2-day window between compromise and public exposure left an extremely narrow oppertunity for detection and response.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including early-series QLogs_Offical MIX batches from May 2025. Run a scan at HEROIC's breach scanner to check whether your credentials were among those exposed in the May 12 collection.
Breach Breakdown
21,009 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds