One Telegram Post. 58 Million Records. The TXTLOG_ALIEN – 700 Log Had 14 Million Stolen Credentials.
HEROIC analysts detected the TXTLOG_ALIEN - 700 stealer log posted to a Telegram channel on January 21, 2025. This file was the largest in the ALIEN series observed that day, containing approximately 58 million total records. From that raw count, analysts identified 13,771,372 unique email addresses, each paired with a plaintext password and a homepage URL showing where the credential was originally captured. The distribution method, a public Telegram channel, meant this data became accessible to a wide range of malicious actors immediately after posting.
Why 58 Million Raw Records Translates Into Immediate Account Risk
The size of this log is significant because it means the credential sweep was unusually broad. Infostealer operations targeting this many endpoints produce a diverse dataset that spans countries, industries, and service types. Attackers who obtained this file did not have to target a specific platform. They could test any of the 14 million unique email and password pairs against any login system they chose. Because the passwords are in plaintext, there is no delay between obtaining the file and attempting to use its contents.
What Was Exposed in the TXTLOG_ALIEN - 700 Log
- Email addresses (approximately 14 million unique)
- Plaintext passwords paired directly with each email
- Homepage URLs pinpointing the sites where each credential was taken
Why This Matters: Scale Drives Credential Stuffing at Industrial Volume
Credential stuffing attacks succeed through volume. The more valid pairs an attacker has, the more accounts they can compromise before detection systems catch on. A log with 14 million entries gives an attacker an enormous starting inventory. Even a modest success rate of one percent means over 100,000 accounts accessed without permission. Those accounts can then be harvested for financial data, used to make fraudulent purchases, drained of loyalty points, or leveraged as entry points into corporate networks if any of the compromised accounts belong to employees.
How the ALIEN Stealer Log Series Operates
The ALIEN series represents a sustained credential harvesting operation. Infostealer malware is distributed to victims through phishing, pirated software, and malicious browser extensions. Once installed, it reads saved passwords, session tokens, and form data directly from the browser, then packages everything into a numbered log file. These files are sequentially numbered and released in batches, with TXTLOG_ALIEN - 700 representing one of hundreds of releases in this ongoing campaign. The use of Telegram for distribution allows the operator to reach a large audience quickly while maintaining a degree of operational anonymity.
Check If Your Email Was in the TXTLOG_ALIEN - 700 File
HEROIC's free breach scanner covers more than 400 billion compromised records sourced from Telegram stealer logs, dark web forums, and data dumps. If your email address is in TXTLOG_ALIEN - 700 or any of the surrounding ALIEN series logs, HEROIC will show you. Check your exposure now at HEROIC and get a clear picture of where your credentials have been compromised.
Breach Breakdown
13,771,372 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds