Slurm Logs Hack: Passwords of 20,523 HPC Users Leaked
HEROIC's DarkHive intelligence system discovered the Slurm Logs stealer log breach, exposing 20,523 records. The incident occured in April 2025, when a Telegram user uploaded stolen credential data on April 3, 2025. The exposed records included email addresses, plaintext passwords, and URLs associated with systems running the Slurm workload manager in high-performance computing environments.
Why This Is Dangerous
Attackers with access to 20,000 plaintext credentials can immediately launch account takeover campaigns against research institutions and enterprises running Slurm clusters. The exposed endpoint and API host URLs in this breach enable attackers to bypass standard login flows and interact directly with backend systems. Compromised HPC infrastructure gives attackers access to sensitive scientific data, proprietary computational models, and the ability to hijack expensive computing resources for cryptomining or botnets.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
Credential stuffing operations powered by dumps like this one test stolen credentials against banking, email, and cloud platforms in fully automated cycles. Users who recieve the same password across several services face account compromise on all of them from a single data point. Organizations that run Slurm clusters for research or enterprise computing face the risk of thier most sensitive projects being accessed or disrupted by attackers who gain cluster administrator credentials from this breach.
How Stealer Log Works
Stealer log malware typically infects victims through spear-phishing emails targeting developers and system administrators, fake software installers, or compromised browser extensions. Once the malware runs, it scans for saved browser passwords, authentication tokens, and SSH keys, then packages everything into a structured log. The log file gets transmitted to attacker-controlled infrastructure and then posted publicly on Telegram channels where criminal communities use the data to launch seperate fraud campaigns against each exposed victim.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like Slurm Logs uploaded by Slurm Logs Free logs. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
20,523 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds