ALIEN TXTBASE is a Telegram-distributed infostealer log corpus that leaksear.ch indexes at exactly 8,638,292,855 records, clearly labeled here as the leaksear.ch indexed count (leaksear.ch metadata). Public Have I Been Pwned reporting describes a different scale, 23 billion rows and 284M unique email addresses, so those public figures should be read as HIBP account and row metrics, not the leaksear.ch indexed count Have I Been Pwned.
What happened
The leaksear.ch metadata records the breach date as February 15, 2025, the reporter as HaveIBeenPwned, and the leaksear.ch index date as July 7, 2026 (leaksear.ch metadata). HIBP's public breach record says 23 billion rows of stealer logs were obtained in February 2025 from a Telegram channel known as ALIEN TXTBASE and contained email addresses, the websites where they were entered, and passwords; the HIBP API lists the incident as a stealer log with breach date 2025-02-15, added date 2025-02-25, PwnCount 284,132,969, and data classes email addresses and passwords Have I Been Pwned breach record Have I Been Pwned API record. Troy Hunt's technical write-up says HIBP ingested 1.5TB of ALIEN TXTBASE data, described publicly as 23 billion rows, 493 million unique website and email address pairs, 284M unique email addresses, 244M previously unseen passwords added to Pwned Passwords, and 199M existing password counts updated Troy Hunt. BleepingComputer also summarized the HIBP addition as over 284 million accounts stolen by infostealer malware from the ALIEN TXTBASE Telegram channel BleepingComputer.
What data was exposed
leaksear.ch indexed count: 8,638,292,855 records (leaksear.ch metadata). Searchable fields in this leaksear.ch index are email, password, and username; other stored fields are credential context login and provenance or target context source_file and url, and the metadata does not state that those other stored fields are searchable (leaksear.ch metadata). Public HIBP pages list compromised data classes as email addresses and passwords, which is a public HIBP view and does not replace the leaksear.ch field inventory for this index Have I Been Pwned breach record.
Why this matters
Infostealer logs are useful to incident responders because they combine identity fields with target service context, allowing teams to prioritize credential rotation, session invalidation, endpoint investigation, and watchlisting around exposed accounts without circulating raw secrets. Researchers should treat ALIEN TXTBASE matches as leads rather than proof of a fresh compromise of every named service, because Hunt noted that stealer log corpora can include legitimate data as well as junk, fabricated email addresses, or websites that were never actually used Troy Hunt. ASD's Australian Cyber Security Centre warns that infostealer malware in general can collect usernames, passwords, browser data, cookies, files, and system information, and that stolen valid credentials can enable initial access leading to ransomware, extortion, business email compromise, and intellectual property theft ASD ACSC. For organizations, the practical risk is not only password reuse; stored URLs and log context can point to business systems, SaaS platforms, and remote access portals where MFA, session lifetime controls, and endpoint hygiene should be validated ASD ACSC.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include email, password, and username.