Breach Intelligence Report 17 Sep 2025

TOR_LOG BR 95logs: 2,100 Records Exposed (September 2023)

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,100
Source Type Stealer log
Origin Telegram
Password Type plaintext

95 Log Files, Two Countries: How Cross-Border Stealer Operations Work

TOR_LOG BR 95logs carries two geographic signals in its name. "BR" marks the logs as Brazil-sourced -- devices compromised in or connected to Brazil. Yet the breach record shows United States as the affected country, meaning the credentials extracted from those Brazilian endpoints were pointing at US-based services and platforms. That's not unusual: infostealer malware harvests whatever's in the browser, regardless of where the service is hosted. The 95 devices in this batch were in Brazil; the accounts they were logged into were mostly American.


TOR_LOG BR 95logs (September 2023): Breach Summary

  • Records Exposed: 2,100
  • Data Types: Usernames, plaintext passwords, endpoint URLs, API hosts
  • Breach Type: Stealer log
  • Date Leaked: September 26, 2023

What "BR" Tells Us About the Infection Campaign

Regional designations in stealer log batch names -- BR for Brazil, MX for Mexico, and so on -- typically reflect where the infected endpoints were located, not where the credentials grant access. A user in Brazil might be logged into Gmail, Dropbox, Shopify, or any US-hosted platform. When an infostealer hits that device, it harvests every saved credential, endpoint URL, and API host in the browser, irrespective of where those services are based.

TOR_LOG BR 95logs thus tells us the campaign targeted Brazilian endpoints specifically -- perhaps through region-specific phishing, Brazilian-language malware distributoin, or a compromised software distributor. The 95 devices affected yielded 2,100 records, averaging roughly 22 credentials per machine. That's a healthy per-device yield suggesting these were active, multi-service users with substantial browser credential stores.


The TOR_LOG Series: A Multi-Geography Brand

TOR_LOG BR 95logs is part of the same TOR_LOG brand as TOR_LOG MIXED 308logs, which also appeared in the September 26-27, 2023 cluster. Where MIXED aggregated logs from multiple sources without geographic specificity, BR is a geographically targeted release -- a deliberate segmentation of the operator's inventory by infection geography.

This kind of segmentation is a marker of operational sophistication. Rather than dumping everything in one undifferentiated pile, the TOR_LOG operator curates releases by region and source type. That suggests organized infrastructure: separate collection channels by geography, quality filtering, and deliberate release strategy rather than bulk dumping.


Small Batches in the September 26 Cluster

At 2,100 records from 95 devices, TOR_LOG BR is one of the smaller batches in the September 26-27 clearing event. But small batches in a coordinated release serve a different purpose than large ones. Large batches (like the 86,386-record JUNE 7 - 4121 LOGS) provide volume. Small attributed batches like TOR_LOG BR 95logs establish operator presence and demonstrate geographic reach -- signaling to buyers that the TOR_LOG brand can deliver regional targeting on demand.

For victims in this batch, the small size provides no protection. Plaintext credentials don't expire because they were part of a modest haul. Whether your login was one of 2,100 or one of 86,386, the access risk is identicle.


Check If Your Credentials Were Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records -- including regional stealer batches like TOR_LOG BR 95logs. Run a free scan to find out if your email or password has appeared in any known breach or leak.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 17 Sep 2025
Check in 5 seconds

2,100 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,451 scanned today
Breach Rank #21,854 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $15.2K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance