XenoLogs Stealer Log Silently Exposed 86,251 Login Records
XenoLogs Stealer Log Exposes 86,251 Records
In September 2025, HEROIC analysts identified a stealer log file, labeled "XenoLogs," that a Telegram user uploaded to the dark web. The file contains 86,251 records pulled from infected devices, with each entry pairing an email address with a plaintext password and the URL of the login page it was used on.
Why the XenoLogs Leak Is Dangerous
The passwords in this dataset were captured and shared in plaintext, meaning anyone who downloads the file can use the credentials immediately without cracking or guessing anything. Since each record also lists the exact site the login belongs to, attackers can quickly sort the data by service and target the accounts most likely to hold money or personal information.
What Was Exposed in the XenoLogs File
- Email addresses
- Plaintext passwords
- URLs of the associated login pages
Why This Matters If You Reuse Passwords
Data like the XenoLogs file is exactly what fuels credential stuffing, the practice of testing stolen email and password pairs against many other websites at once. Anyone who reused a leaked password on a banking, email, or shopping account faces a real risk of account takeover, financial fraud, or identity theft, especially since these credentials were still active enough to be worth stealing.
How Stealer Logs Like XenoLogs Get Built
Stealer logs are produced by malware that infects a computer and silently harvests everything saved in the browser, including stored passwords, autofill fields, and session cookies. Once collected, the stolen data is bundled into a single file and distributed on dark web marketplaces or Telegram channels, much like the one behind this XenoLogs leak. Because the malware pulls current, saved login data straight from the browser, these logs tend to be more accurate and dangerous than older leaked password lists.
Check If You Are Affected by the XenoLogs Leak
Even a leak of this size can affect people who never expected to be part of it. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this XenoLogs file, so you can find out in seconds whether your information was exposed and change any passwords you've been reusing.
Breach Breakdown
86,251 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds