TOR_LOG BR 95logs: 2,100 Records Exposed (September 2023)
95 Log Files, Two Countries: How Cross-Border Stealer Operations Work
TOR_LOG BR 95logs carries two geographic signals in its name. "BR" marks the logs as Brazil-sourced -- devices compromised in or connected to Brazil. Yet the breach record shows United States as the affected country, meaning the credentials extracted from those Brazilian endpoints were pointing at US-based services and platforms. That's not unusual: infostealer malware harvests whatever's in the browser, regardless of where the service is hosted. The 95 devices in this batch were in Brazil; the accounts they were logged into were mostly American.
TOR_LOG BR 95logs (September 2023): Breach Summary
- Records Exposed: 2,100
- Data Types: Usernames, plaintext passwords, endpoint URLs, API hosts
- Breach Type: Stealer log
- Date Leaked: September 26, 2023
What "BR" Tells Us About the Infection Campaign
Regional designations in stealer log batch names -- BR for Brazil, MX for Mexico, and so on -- typically reflect where the infected endpoints were located, not where the credentials grant access. A user in Brazil might be logged into Gmail, Dropbox, Shopify, or any US-hosted platform. When an infostealer hits that device, it harvests every saved credential, endpoint URL, and API host in the browser, irrespective of where those services are based.
TOR_LOG BR 95logs thus tells us the campaign targeted Brazilian endpoints specifically -- perhaps through region-specific phishing, Brazilian-language malware distributoin, or a compromised software distributor. The 95 devices affected yielded 2,100 records, averaging roughly 22 credentials per machine. That's a healthy per-device yield suggesting these were active, multi-service users with substantial browser credential stores.
The TOR_LOG Series: A Multi-Geography Brand
TOR_LOG BR 95logs is part of the same TOR_LOG brand as TOR_LOG MIXED 308logs, which also appeared in the September 26-27, 2023 cluster. Where MIXED aggregated logs from multiple sources without geographic specificity, BR is a geographically targeted release -- a deliberate segmentation of the operator's inventory by infection geography.
This kind of segmentation is a marker of operational sophistication. Rather than dumping everything in one undifferentiated pile, the TOR_LOG operator curates releases by region and source type. That suggests organized infrastructure: separate collection channels by geography, quality filtering, and deliberate release strategy rather than bulk dumping.
Small Batches in the September 26 Cluster
At 2,100 records from 95 devices, TOR_LOG BR is one of the smaller batches in the September 26-27 clearing event. But small batches in a coordinated release serve a different purpose than large ones. Large batches (like the 86,386-record JUNE 7 - 4121 LOGS) provide volume. Small attributed batches like TOR_LOG BR 95logs establish operator presence and demonstrate geographic reach -- signaling to buyers that the TOR_LOG brand can deliver regional targeting on demand.
For victims in this batch, the small size provides no protection. Plaintext credentials don't expire because they were part of a modest haul. Whether your login was one of 2,100 or one of 86,386, the access risk is identicle.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including regional stealer batches like TOR_LOG BR 95logs. Run a free scan to find out if your email or password has appeared in any known breach or leak.
Breach Breakdown
2,100 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds