Breach Intelligence Report 20 Mar 2025

One Telegram Post. 58 Million Records. The TXTLOG_ALIEN – 700 Log Had 14 Million Stolen Credentials.

HEROIC
HEROIC Threat Intelligence Team
Email Address Plaintext Password Homepage Url
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 13,771,372
Source Type Database
Origin Telegram
Password Type Plaintext

HEROIC analysts detected the TXTLOG_ALIEN - 700 stealer log posted to a Telegram channel on January 21, 2025. This file was the largest in the ALIEN series observed that day, containing approximately 58 million total records. From that raw count, analysts identified 13,771,372 unique email addresses, each paired with a plaintext password and a homepage URL showing where the credential was originally captured. The distribution method, a public Telegram channel, meant this data became accessible to a wide range of malicious actors immediately after posting.


Why 58 Million Raw Records Translates Into Immediate Account Risk

The size of this log is significant because it means the credential sweep was unusually broad. Infostealer operations targeting this many endpoints produce a diverse dataset that spans countries, industries, and service types. Attackers who obtained this file did not have to target a specific platform. They could test any of the 14 million unique email and password pairs against any login system they chose. Because the passwords are in plaintext, there is no delay between obtaining the file and attempting to use its contents.


What Was Exposed in the TXTLOG_ALIEN - 700 Log

  • Email addresses (approximately 14 million unique)
  • Plaintext passwords paired directly with each email
  • Homepage URLs pinpointing the sites where each credential was taken

Why This Matters: Scale Drives Credential Stuffing at Industrial Volume

Credential stuffing attacks succeed through volume. The more valid pairs an attacker has, the more accounts they can compromise before detection systems catch on. A log with 14 million entries gives an attacker an enormous starting inventory. Even a modest success rate of one percent means over 100,000 accounts accessed without permission. Those accounts can then be harvested for financial data, used to make fraudulent purchases, drained of loyalty points, or leveraged as entry points into corporate networks if any of the compromised accounts belong to employees.


How the ALIEN Stealer Log Series Operates

The ALIEN series represents a sustained credential harvesting operation. Infostealer malware is distributed to victims through phishing, pirated software, and malicious browser extensions. Once installed, it reads saved passwords, session tokens, and form data directly from the browser, then packages everything into a numbered log file. These files are sequentially numbered and released in batches, with TXTLOG_ALIEN - 700 representing one of hundreds of releases in this ongoing campaign. The use of Telegram for distribution allows the operator to reach a large audience quickly while maintaining a degree of operational anonymity.


Check If Your Email Was in the TXTLOG_ALIEN - 700 File

HEROIC's free breach scanner covers more than 400 billion compromised records sourced from Telegram stealer logs, dark web forums, and data dumps. If your email address is in TXTLOG_ALIEN - 700 or any of the surrounding ALIEN series logs, HEROIC will show you. Check your exposure now at HEROIC and get a clear picture of where your credentials have been compromised.

Breach Breakdown

Domain N/A
Leaked Data Email Address, Plaintext Password, HomePage URL
Password Types Plaintext
Date Leaked 20 Mar 2025
Check in 5 seconds

13,771,372 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,010 scanned today
Breach Rank #207 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $99.6M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance