TOR_LOG MIX 235logs: 4,035 US Stealer Log Credentials Exposed Oct 4, 2023
TOR_LOG MIX 235logs: Completing the Oct 4 Two-Batch Picture
TOR_LOG MIX 235logs is the second of two TOR_LOG MIX batches released on October 4, 2023. The first -- TOR_LOG MIX 221log -- contributed 4,195 records from 221 source files the same day. Combined, the two Oct 4 batches represent 456 endpoint captures and 8,230 US credentials. A third TOR_LOG MIX batch (no file-count suffix, 7,675 records) was released a day earlier on October 3, bringing the confirmed TOR_LOG MIX series total to 15,905 records across three batches spanning Oct 3-4. The series total places TOR_LOG MIX among the more substantail multi-batch operators in the pre-Oct 6 window.
TOR_LOG MIX 235logs (October 2023): Stealer Log Summary
- Records Exposed: 4,035
- Data Types: Email addresses, plaintext passwords, URLs
- Breach Type: Stealer log -- credentials harvested from malware-infected endpoints, not a direct database breach
- Password Type: Plaintext -- captured directly from browser sessions and credential stores by infostealer malware
- Country: United States
- Date Leaked: October 4, 2023
Per-File Yield Comparison: 235logs vs. 221log
TOR_LOG MIX 235logs -- 4,035 records from 235 files -- yields approximately 17.2 records per endpoint. The companion Oct 4 batch, 221log, yields roughly 19 records per file. Both figures are above the dataset average of 11-13 records/file, suggesting TOR_LOG MIX was drawing from a higher-quality endpoint pool than typical broad-deployment infostealer campaigns. The slight drop in yield from 221log to 235logs may reflect incremental inclusion of lower-value endpoint captures as the operator exhausted the higher-yield portion of their available log inventory for the day.
The Three-Batch TOR_LOG MIX Series: Oct 3 and Oct 4
The TOR_LOG MIX name appears across at least three distinct releases: the base "TOR_LOG MIX" batch on October 3 (7,675 records), followed by two numbered batches on October 4 (221log and 235logs). The progression -- an unnumbered base release on Oct 3 followed by two file-count-labeled batches on Oct 4 -- may reflect an evolving naming convention, with the operator adopting explicit file-count sufixes after the first release. The three-batch total of 15,905 records confirms TOR_LOG MIX as an operator with a multi-day presence in the pre-surge window.
Plaintext Passwords and Immediate Exploitation Risk
TOR_LOG MIX 235logs contains plaintext passwords throughout -- credentials extracted from browser sessions and autofill data by infostealer malware. No decryption or cracking is needed before use. Threat actors who acquired this batch on Oct 4 could begin testing credentials against major login portals the same day, a full two days before the Oct 6 cluster made the broader scope of this dataset apparent. Victims with reused passwords across multiple platforms faced compounded risk from each successive TOR_LOG MIX release.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches more than 400 billion exposed records -- including stealer log series like TOR_LOG MIX. If your credentials appear in any of the three TOR_LOG MIX batches, HEROIC will surface the match at no cost. Run a free search at HEROIC's breach scanner.
Breach Breakdown
4,035 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds