Snorlax Data Pool is an infostealer-style credential and device-log dataset with a leaksear.ch indexed count of 105,672,186 records and a listed breach date of October 25, 2025 (leaksear.ch metadata). Public re-checks did not identify a primary breach notice tying the dataset to one named organization, but stealer-log research shows why combined credentials, cookies, browser artifacts, IP addresses, and device identifiers require account-takeover and endpoint triage MITRE ATT&CK, Recorded Future.
What happened
leaksear.ch metadata describes Snorlax Data Pool as an infostealer-style credential and device-log source. The source has no reporter listed, is assigned a breach date of October 25, 2025, and was indexed on July 8, 2026 (leaksear.ch metadata).
One supplied public context link, HIBP's June 2026 Stealer Logs page, reports 56.3 million affected accounts, 56 million unique email addresses across hundreds of millions of stealer-log records, and 124 million unique passwords. Those HIBP figures are HIBP's scale for its own stealer-log breach entry and should not be substituted for Snorlax Data Pool's leaksear.ch indexed count of 105,672,186 records Have I Been Pwned.
The dataset type aligns with known infostealer collection patterns. MITRE ATT&CK documents browser credential theft through browser-specific files, while Flare and DarkOwl describe stealer logs as data packages from infected devices that can include credentials, cookies, browser data, and system details MITRE ATT&CK, Flare, DarkOwl.
What data was exposed
Snorlax Data Pool has a leaksear.ch indexed count of 105,672,186 records (leaksear.ch metadata). Searchable fields listed for this source are: address, country, dateOfBirth, domain, email, ipAddress, name, password, phone, and username (leaksear.ch metadata).
Other stored fields are present for context, but they are not listed as searchable by leaksear.ch metadata. Account, application, and URL context fields include account_identifier, application, profile, record_type, recovery_method, title, url, and source_url. Browser, autofill, and form artifact fields include autofill_form, autofill_value, browser, browser_file, browser_version, form_field, and form_value. Cookie fields include cookie_domain, cookie_expires, cookie_include_subdomains, cookie_name, cookie_path, cookie_secure, and cookie_value. Device and environment fields include build_id, computer_name, hwid, machine_id, operating_system, system_language, and timezone. Location, timing, and source file context fields include location, log_date, zip_code, log_folder, source_file, source_format, source_fragment, source_path, and victim_log_id (leaksear.ch metadata).
Why this matters
For incident responders, this is a credential-exposure and endpoint-compromise signal, not merely a name-and-email leak. The combination of email, username, password, domain, URL context, cookies, IP address, machine identifiers, browser details, and log timing can help prioritize password resets, forced logout, token rotation, endpoint containment, and review of authentication logs.
Credentials saved in browsers map to MITRE ATT&CK T1555.003, and public research notes that stolen session cookies can enable session hijacking or MFA bypass when an authenticated session remains valid MITRE ATT&CK, Recorded Future. ZeroFox also cautions that stealer-log compilations can combine multiple sources and timeframes, so a match should trigger validation and remediation without assuming a single enterprise intrusion ZeroFox.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, country, date of birth, domain, email, ip address, name, password, phone, and username.