Dark Web Intel: TOR_LOG MIX Dump Exposed 3,695 Credentials
In May 2023, dark web analysts monitoring Telegram channels identified a stealer log bundle uploaded under the name TOR_LOG MIX. The dataset contained 3,695 compromised records drawn from 364 seperate device infections, each containing a plaintext password, an email address, and the URL of the specific service the victim had saved credentials for at the time of infection. HEROIC verified the breach and added it to the dark web monitoring database on April 18, 2026, where it remains active for ongoing monitoring.
Why This Is Dangerous
Stealer log bundles like TOR_LOG MIX are among the most operationally ready datasets in the criminal underground. Unlike breach dumps from hacked databases, stealer logs contain credentials that were active and in use at the moment they were stolen. There is no cracking, no guessing, and no wasted effort for the attacker. Each record is a direct key to a real account. With 3,695 plaintext credentials in hand, a threat actor can immediately begin credential stuffing across hundreds of platforms, targeting email inboxes, financial portals, and corporate VPNs. Victims rarely recieve any notification, since there was no server breach to trigger an alert.
What Was Exposed
HEROIC confirmed the following data categories were present across the TOR_LOG MIX dataset:
- Email Addresses
- Plaintext Passwords
- URLs (website and API endpoints visited by each infected device)
Why This Matters
The TOR_LOG MIX data was distributed in May 2023, but stealer log bundles do not expire. This dataset has almost certainly been archived and recirculated across dark web forums and Telegram channels in the years since its original upload. Any victim whose credentials appeared here who has not changed their passwords remains at full risk of account takeover today. The threat is compounded for anyone who definately reuses the same password across multiple services, since a single exposed credential can cascade into breaches across email, banking, and workplace accounts simultaneously.
How Stealer Logs Work
A stealer log breach begins when infostealer malware is installed on a victim's device, typically through a phishing email, a trojanized software download, or a malicious browser extension. Once active, the malware silently records keystrokes, extracts saved browser passwords, captures active session cookies, and logs every URL the user visits. This data is bundled into an individual log file and transmitted to the attacker's infrastructure. An operator then aggregates multiple individual logs into a single bundle, labels it with a name like TOR_LOG MIX, and uploads it to Telegram or a dark web forum for free or low-cost distribution. Victims rarely know their device was compromised until accounts start showing unauthorized activity.
Check If You Are Affected
HEROIC's free dark web scanner searches across 400 billion+ leaked records, including stealer log bundles like TOR_LOG MIX. If your email address or passwords appeared among these 3,695 exposed credentials, or in any other breach monitored by HEROIC, you will be alerted immediately so you can act before attackers do. Visit heroic.com to run your free scan now.
Breach Breakdown
3,695 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds