Telegram – Xavier_Group – 555 Xavier_Log uploaded by a Telegram User
We're seeing a consistent uptick in stealer log drops across Telegram channels, often packaged as "kits" or "dumps" promising access to compromised accounts. What really struck us about this particular log file, shared on the Xavier_Group channel, wasn't its size—approximately 15,021 records—but the specificity of the exposed data. It wasn't just usernames and passwords; it included API hosts and endpoint URLs, suggesting a focus on compromised developer or automation accounts. The data had been circulating for a few days, but we noticed a spike in chatter referencing it across multiple security-focused Telegram groups, indicating wider awareness and potential exploitation.
Telegram's Xavier_Group Leaks 15,000+ Credentials, URLs, and API Hosts
On September 13, 2025, a user on the Telegram channel Xavier_Group uploaded a stealer log file containing 15,021 records. While stealer logs are common, the inclusion of email addresses, plaintext passwords, and crucially, API host URLs and other endpoint URLs, points to a targeted collection effort, likely aimed at compromising accounts with elevated privileges or automated access.
Our team discovered the leak through our routine monitoring of Telegram channels known for hosting and distributing compromised data. It initially caught our attention due to the unusual inclusion of API host and endpoint URLs, suggesting a focus beyond standard user account compromise. The file's sudden appearance, coupled with increased mentions in other security-related Telegram groups, signaled a potential surge in exploitation activity.
This breach matters to enterprises now because it highlights the continued effectiveness of stealer malware in harvesting sensitive credentials and the growing trend of targeting API keys and other programmatic access tokens. The exposure of API hosts and endpoint URLs drastically increases the potential blast radius of a successful compromise, potentially allowing attackers to bypass traditional security controls and directly access sensitive data or critical infrastructure.
- Total records exposed: 15,021
- Types of data included: Email Addresses, Plaintext Passwords, URLs (including API hosts and endpoints)
- Sensitive content types: Potentially sensitive API keys and tokens embedded within the URLs
- Source structure: Stealer log file
- Leak location(s): Telegram channel Xavier_Group
- Date of first appearance: September 13, 2025
External Context & Supporting Evidence
The rise of Telegram as a marketplace for stolen data and hacking tools has been documented extensively. Security researchers at Recorded Future have consistently highlighted the platform's role in facilitating cybercrime, noting the ease with which threat actors can share and monetize compromised information. The Xavier_Group channel itself likely serves as a hub for similar activities, offering a range of stolen data and hacking tools to its members. Similar Telegram channels have been identified as sources for initial access brokers to gain entry to enterprise networks as highlighted by a recent Crowdstrike report.
Analysis of similar stealer logs often reveals overlaps in the targeted applications and services. Researchers at BleepingComputer regularly report on new stealer variants targeting specific password managers, VPN clients, and cryptocurrency wallets. Examining the specific API hosts and endpoints included in the Xavier_Group leak could reveal which applications and services were targeted by the stealer malware, providing valuable insights for incident response and proactive threat hunting.
Breach Breakdown
15,021 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds