Breach Intelligence Report 23 Mar 2026

Was Your Data in the TOR_LOG MIX 301PCS Breach? 5,351 Records

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 5,351
Source Type Stealer log
Origin Telegram
Password Type plaintext

HEROIC discovered 5,351 records exposed in the TOR_LOG MIX 301PCS stealer log breach on October 13, 2024. Despite sharing the 301PCS label with the October 15 drop, this earlier archive came from a different operator persona and carries a substantially larger 5,351-victim footprint, suggesting a separate harvesting infrastructure.


Why This Stealer Log Is Dangerous

Because two unrelated actors are recycling the 301PCS tag, defenders who only check for one instance will miss the other. This archive is roughly four times larger than its namesake two days later, meaning exposure probability is higher for any given user. Plaintext passwords and recorded URLs provide a clear attack roadmap.


What Was Exposed in TOR_LOG MIX 301PCS

  • Email addresses covering personal, work, and catch-all inboxes
  • Plaintext passwords captured at the moment of login
  • URLs showing targeted web apps and internal portals
  • API endpoint URLs useful for lateral movement
  • System fingerprint data identifying specific hosts

The mix of consumer and enterprise URL patterns suggests the operator was not filtering victim type.


Why This Matters

Attacker personas matter when assessing risk. This operator appears to recycle a popular tag to improve visibility in crowded Telegram marketplaces, a reminder that log names are branding rather than provenance. Organizations should assume any recurring tag represents multiple independent archives and check each one.


How a Stealer Log Like TOR_LOG MIX 301PCS Works

Stealer binaries land via phishing attachments, drive-by downloads, or malicious NPM and PyPI packages. On execution they sweep Chromium, Firefox, and Gecko-based browsers for saved credentials, decrypt them using the logged-in user's DPAPI key, and upload the output. Operators relabel the output to match trending tags like 301PCS before redistributing.


Check If You Are Affected

HEROIC monitors the world's largest breach database with over 400 billion compromised records. Run a free scan to see if your email, passwords, or accounts appear in the TOR_LOG MIX 301PCS leak or other major breaches.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 23 Mar 2026
Check in 5 seconds

5,351 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,538 scanned today
Breach Rank #17,839 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $38.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance