Breach Intelligence Report 18 Apr 2026

Dark Web Intel: TOR_LOG MIX Dump Exposed 3,695 Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs TOR_LOG MIX 364logs uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 3,695
Source Type Stealer log
Origin United States
Password Type plaintext

In May 2023, dark web analysts monitoring Telegram channels identified a stealer log bundle uploaded under the name TOR_LOG MIX. The dataset contained 3,695 compromised records drawn from 364 seperate device infections, each containing a plaintext password, an email address, and the URL of the specific service the victim had saved credentials for at the time of infection. HEROIC verified the breach and added it to the dark web monitoring database on April 18, 2026, where it remains active for ongoing monitoring.


Why This Is Dangerous

Stealer log bundles like TOR_LOG MIX are among the most operationally ready datasets in the criminal underground. Unlike breach dumps from hacked databases, stealer logs contain credentials that were active and in use at the moment they were stolen. There is no cracking, no guessing, and no wasted effort for the attacker. Each record is a direct key to a real account. With 3,695 plaintext credentials in hand, a threat actor can immediately begin credential stuffing across hundreds of platforms, targeting email inboxes, financial portals, and corporate VPNs. Victims rarely recieve any notification, since there was no server breach to trigger an alert.


What Was Exposed

HEROIC confirmed the following data categories were present across the TOR_LOG MIX dataset:

  • Email Addresses
  • Plaintext Passwords
  • URLs (website and API endpoints visited by each infected device)

Why This Matters

The TOR_LOG MIX data was distributed in May 2023, but stealer log bundles do not expire. This dataset has almost certainly been archived and recirculated across dark web forums and Telegram channels in the years since its original upload. Any victim whose credentials appeared here who has not changed their passwords remains at full risk of account takeover today. The threat is compounded for anyone who definately reuses the same password across multiple services, since a single exposed credential can cascade into breaches across email, banking, and workplace accounts simultaneously.


How Stealer Logs Work

A stealer log breach begins when infostealer malware is installed on a victim's device, typically through a phishing email, a trojanized software download, or a malicious browser extension. Once active, the malware silently records keystrokes, extracts saved browser passwords, captures active session cookies, and logs every URL the user visits. This data is bundled into an individual log file and transmitted to the attacker's infrastructure. An operator then aggregates multiple individual logs into a single bundle, labels it with a name like TOR_LOG MIX, and uploads it to Telegram or a dark web forum for free or low-cost distribution. Victims rarely know their device was compromised until accounts start showing unauthorized activity.


Check If You Are Affected

HEROIC's free dark web scanner searches across 400 billion+ leaked records, including stealer log bundles like TOR_LOG MIX. If your email address or passwords appeared among these 3,695 exposed credentials, or in any other breach monitored by HEROIC, you will be alerted immediately so you can act before attackers do. Visit heroic.com to run your free scan now.

Breach Breakdown

Domain TOR_LOG MIX 364logs uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 18 Apr 2026
Check in 5 seconds

3,695 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,218 scanned today
Breach Rank #19,233 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $26.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance