Breach Intelligence Report 15 May 2026

U.S. Users Hit: TOR_LOG MIX Telegram Stealer Log Leaks 10,440 Records

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs TOR_LOG MIX uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 10,440
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts confirmed a stealer log file surfaced on Telegram in September 2023 under the name TOR_LOG MIX, exposing 10,440 records containing email addresses, plaintext passwords, and URLs. The dataset was shared publicly by an anonymous Telegram user and is classified as a verified stealer log, meaning the credentials in it were captured live from infected machines rather than pulled from a breached server. The United States is identified as the primary country of origin for this data, making this a significant domestic credential exposure event.


Why This Dataset Is Dangerous for U.S. Users

Stealer logs harvested from U.S.-based devices are particularly high-value to attackers. American users tend to have more linked financial accounts, cloud storage, and workplace tools tied to their primary email addresses. A single set of credentials can open the door to bank accounts, payroll portals, healthcare systems, and corporate email, all at once.

The TOR_LOG MIX naming also suggests the dataset draws from multiple sources, mixing logs from different infostealer campaigns. That makes it broader in scope than a single-origin log, potentially reaching across different device types, browsers, and service categories.


What Was Exposed in TOR_LOG MIX

  • Email Addresses: Used as login names across most platforms, and the key to triggering password resets on any connected account
  • Plaintext Passwords: Captured as typed, no cracking required, functional immediately upon use
  • URLs: Pinpoint the exact services where these credentials apply, from consumer platforms to API hosts and internal portals

The presence of API host URLs in stealer logs like this one is a reminder that the risk extends beyound individual users. Developers and IT professionals whose credentials were captured may have inadvertently exposed backend systems and internal infrastructure.


Why This Matters: U.S. Credentials Are a High-Value Target

Credential stuffing campaigns that use U.S.-origin data are among the most profitable for cybercriminals. Attackers run harvested email and password pairs against platforms like financial institutions, e-commerce sites, and subscription services, relying on password reuse to multiply access.

Identity theft is a common downstream consequence. Once an attacker is inside an email account, they can intercept two-factor authentication codes, access linked social accounts, and request password resets on every other platform. The initial stolen credential becomes a skeleton key for the victim's entire digital life.

Account takeover fraud, where criminals use hijacked accounts to make purchaces or redirect funds, is another direct risk from data like this. With verified email addresses and working passwords in hand, attackers do not need to do much additional work.


How Stealer Logs Like TOR_LOG MIX Are Created

Infostealer malware is the engine behind stealer log creation. It gets onto a victim's device through phishing links, pirated software, malicious browser extensions, or fake utility tools. Once installed, it operates without any visible sign to the user.

The malware targets browser password managers, session cookies, autofill databases, and any credentials typed or pasted into login forms. It records the URL where each credential is used and packages all of it into a structured log file. That file is then uploaded to a command-and-control server and eventually shared or sold through channels like Telegram.

The TOR_LOG MIX label indicates this particular file aggregates logs from multiple collection sessions, potentially from different infostealer variants. Mixed log files like this one tend to have wide geographic and platform coverage, compounding the risk for anyone whose credentials ended up in the dataset.


Check If Your U.S.-Based Account Was Caught in TOR_LOG MIX

HEROIC indexes over 400 billion records from breach datasets, stealer logs, and dark web sources, including files like TOR_LOG MIX that circulate on Telegram. If your credentials were captured in this dataset, HEROIC's free breach scanner can identify your exposure.

Search your email address at HEROIC to find out what is currenly known about your data online and take steps to secure your accounts before someone else does.

Breach Breakdown

Domain TOR_LOG MIX uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 15 May 2026
Check in 5 seconds

10,440 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,693 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $75.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance