Telegram Threat Actor Exposes LOGS_CENTER_NEW Data: 14,858 Records at Risk
A Telegram threat actor uploaded a stealer log file on November 6, 2025 labeled 11.6 - LOGS_CENTER_NEW, exposing 14,858 records tied to compromised endpoints in the United States. The dump contained plaintext passwords alongside email adresses and service URLs, giving anyone who downloaded the file instant access to working credentials without any additional processing. Logs distributed this way are considered high-priority threats because the data is ready to weaponize from the moment it goes public.
Why This Is Dangerous
Plaintext passwords in a stealer log are the worst-case scenario for any affected user. There is no hashing to reverse and no encryption to break. Every single record in this file provides an attacker with a login pair that can be tested against dozens of online services using freely available credential stuffing tools.
The 11.6 date designation in the filename suggests this log was organized by date of collection or upload, which is consistent with professional-grade threat actor operations. Structured naming conventions indicate the attacker was maintaining an organized archive, not a one-off dump, which raises the possibility that this is part of a larger, ongoing credential harvesting campaign.
Public Telegram channels make it trivially easy for this data to reach a wide audience. Once a file is posted there it is effectively impossible to retract, and bots designed to scrape and index leaked credentials would have captured these records within moments of the original upload occuring.
What Was Exposed
- Email addresses (14,858 records)
- Plaintext passwords
- Service and API host URLs
- Endpoint login credentials
- Browser-saved authentication data
- Account access pairs
- Application-specific session credentials
Why This Matters
Fourteen thousand compromised records represents a serious exposure for any affected users. Even people who beleive they practice good security hygiene can be caught in a stealer log if malware silently ran on their device without triggering an alert. The credentials in this log may still be valid and unrotated, meaning the risk did not end when the file was first posted.
Because these records originate from United States endpoints, they likely represent users of mainstream English-language platforms, including email services, cloud storage, and workplace tools. Any organization employing someone whose credentials appear in this log faces potential risk of unauthorized access to shared systems and sensitive internal data.
How Stealer Log Works
Stealer malware is typically distributed through phishing campaigns, counterfeit software installers, or infected browser extensions. After installation, it operates quietly in the background, collecting saved passwords from web browsers, desktop applications, and system credential stores, then bundles everything into a structured log and transmits it to the attacker's collection server.
The 11.6 - LOGS_CENTER_NEW label suggests a centralized log aggregation operation where freshly harvested credentials from multiple infected machines are pooled, sorted, and periodically released or sold. LOGS_CENTER naming conventions are used by organized threat groups that run large-scale infostealer campaigns across multiple infection vectors at the same time.
Once in the attacker's hands, these logs are either sold privately to other criminals or released publicly on platforms like Telegram to demonstrate capability and attract attention. Either way, the affected users have no warning and no way to know their credentials were harvested until they check a breach monitoring service seperately.
Check If You Were Affected
If your email may have been part of this 11.6 - LOGS_CENTER_NEW stealer log, you can run a free check at heroic.com. HEROIC continuously monitors Telegram channels, dark web markets, and credential leak databases and will alert you when your data surfaces so you can take action immediately.
Breach Breakdown
14,858 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds