The Xavier_Log Stealer Dump Contains Exactly 3,760 Stolen Logins
On 04-Aug-2026, HEROIC analysts identified a stealer log named Xavier_Log - 195 Xavier_Group free circulating on Telegram. The file contains exactly 3,760 records harvested from infected devices, each including an email address, a plaintext password, and the URL of the account it belongs to.
Why This Is Dangerous
The "195" in the file name suggests this is the 195th batch released by the group behind it, and the word "free" indicates it was distributed at no cost to build a following on Telegram. Every one of the 3,760 records includes a working plaintext password already matched to its login URL, so no additional effort is needed to use it.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs for each affected login
Why This Matters
A group numbering its releases into the hundreds, like "Xavier_Group," suggests an ongoing, high-volume operation rather than a one-time leak. If your credentials are among these 3,760 records and you've reused that password on other accounts, an attacker could use it to gain access elsewhere too.
How Stealer Logs Work
Stealer logs are generated by information-stealing malware that quietly copies saved browser passwords, autofill data, and session details from an infected device. Groups that produce these logs at scale, like Xavier_Group, often number and release their batches sequentially, offering some for free on Telegram to attract buyers to their paid releases.
Check If You Are Affected
With 3,760 records in this batch alone, checking your exposure takes just a moment. HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this stealer log, so you can confirm whether you're affected.
Breach Breakdown
3,760 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds