What Happens to Stealer Logs After the Sale

A stealer log does not end its life when someone buys it. The buyer may work it themselves, but the data often keeps moving: it is split into smaller lists, loaded into search services, sold by the slice, and eventually posted as a free download. Each step spreads it further and makes it easier to find.
This post follows a log after the sale, based on what public listings on underground forums show, and explains why "it's an old log" is not a reason to relax.
How we know
We read public thread titles, dates, replies and views on database and log boards of several underground forums, without logging in. For the larger boards we read only the first pages. We did not open threads, buy anything or download files. Titles are advertisements. Sizes, prices and success claims are unverified, and much of the material is likely recycled. We are not naming forums or sellers.
Step 1: Logs are sliced into lists
One large log collection can be repackaged many ways. Listings say the data comes "from logs" and split it by category:
- By provider: lists of mailboxes at large internet and email providers, ranging from a few million lines to over a hundred million.
- By country: lists labeled for Germany, the UK, Italy, France and others.
- By sector or domain type: lists for education domains, and corporate domains in Turkey, Finland, South Africa, Taiwan and Germany, from under a million lines to tens of millions.
- By theme: game accounts, crypto accounts, streaming and shopping.
- By malware family, country and device: some batches are labeled with the stealer that produced them, the country and the operating system, for example "2,500 logs, Canada, Windows 10".
Drops can also be very recent. One dump on a public stealer-log board was titled "freshly dumped" with the current date, and listings on that board range from a few hundred thousand lines to over a hundred million, tagged "fresh", "private" or "HQ".

Public listing titles offering data "from logs" split by provider, country and theme. Usernames, avatars and shop names are blurred, and the forum's name is removed.
The effect is that a log about one employee does not stay attached to that employee. The corporate login inside it may end up in a list of "corporate" credentials for your country.
For defenders: assume that a credential seen once can appear in a list you would not think to check.
Step 2: Databases are searchable by target
The biggest listings are not lists at all. They are searchable databases of URL, login and password lines: "10 billion+ lines", "1 TB", and one cloud claiming about 35 billion lines. Sellers invite buyers to "search your request" or "extract your target", sometimes through a chat-bot or with search software included.
Advertised prices span a wide range: roughly $40 for a large one-off extract, $70 to $650 a month for cloud subscriptions, and about $800 for a 53-million-line private list, often with a 500,000-line sample offered first. Treat all of these as claims.
Some sellers price by the query instead. One 2024 listing offered to pull a buyer's request from a 1.5 TB collection for a fixed $30, and others run chat-bots that take the request and return matches, or advertise "no download limit" access to a searchable system.
The important point is the interface. A buyer does not need to buy everything. They type your domain and pay for the matches.
For defenders: monitor your own domains and the services your staff use, because that is exactly what a buyer will search.
Step 3: "Valid" lists and checking
Some listings advertise "valid" or "ex-valid" lists, meaning credentials that were already tested. Others sell or share checker tools that test logins against mail providers, streaming services, cloud suites, retail sites and banks at scale. Many of the tools in the listings are cracked or leaked copies.
Testing is what turns a raw list into working access, and it happens in bulk and without anyone watching.
For defenders: credential-stuffing protection, such as rate limiting, breached-password checks and MFA, matters even when your own systems were never breached.
Step 4: Free dumps
The final stage is the giveaway. A public database board shows releases of URL, login and password files labeled as logs, with sizes from about 5 million to more than 700 million lines, plus mail and password lists by country and a newer format for Android app logins. Some threads draw thousands of views and a few dozen replies.
Free dumps are usually recycled material, but that is the point. Once data is public, anyone can pick it up and try it.
Step 5: Single accounts on storefronts (what we think we saw)
Further along, some of the same material appears to end up one account at a time. We looked at the public front of an account shop, without logging in and without buying anything. Its "Webmail Business" category listed one business email account per row. Each row showed the site's domain, a country, a price, a seller number, a "Proof" button, and a source label of "Hacked". The login details were hidden until a buyer signed in.
The prices we saw were roughly $19 to $56 per account. The organizations behind the listings were spread across the world, with domain endings including .com, .co.uk, .com.vn, .co.th, .cz, .fr, .es and .jp, and one government domain. Several listings were five or six months old according to the shop's own date column, and the shop's filter let buyers search by site, country and seller.

Public listings in an account-shop category. We covered the name part of each domain and kept the ending, covered the seller numbers, and the login details are hidden until a buyer signs in.
We want to be careful here. The listings do not say where the accounts came from, so we cannot show that they came from stealer logs. Credential stuffing, phishing and old database leaks would look the same from the outside. But the shape fits: entries keyed by site, with a login, sold cheaply in bulk. It matches how log data looks once it has been sliced by domain.
For defenders: a login for your organization may be offered individually, months after the infection. Do not assume a credential is no longer for sale because it is old.
Why old logs stay dangerous
We saw one service that offers to process social-media logs "even from 2020". Free dumps, big searchable databases and checkers all mean stolen credentials get tried again long after the original infection. Session cookies expire, but reused passwords do not.
That is why we would not tell a security team "this log is two years old, so we can ignore it." The safe response is the same whatever the age: rotate the credentials, invalidate any sessions, and turn on MFA wherever it is missing.
What to do
| Stage | Risk | Action |
|---|---|---|
| Sliced lists | Your credentials appear in a list by country, sector or provider | Monitor by domain and by employee account |
| Searchable databases | A buyer queries your domain directly | Track your domains in exposure data, and alert on new matches |
| Checkers and valid lists | Stolen logins are tested at scale | Rate limiting, breached-password checks, MFA |
| Free dumps | Old data reaches a wider audience | Rotate credentials whatever the age of the exposure |
| Single-account storefronts | A login for your organization is sold on its own, months later | Monitor for your domains and rotate credentials even for old exposures |
If you find a match
- Identify the affected account or device.
- Invalidate active sessions and rotate every credential involved.
- Turn on MFA, preferably hardware-backed.
- Review authentication logs for access you don't recognize.
- Check for the same password reused on other services.
For the buyer's side, read what buyers want in a stealer log. To see how logs are produced, read the stealer log supply chain. For detection, see our stealer log detection guide, and for the basics, what stealer logs are.
Common questions
What happens to a stealer log after it is sold? It can be worked by the buyer, split into lists by provider, country or sector, loaded into searchable databases, tested with checker tools, and later released as a free dump.
Are old stealer logs still a risk? Yes. Older logs are still used, and reused passwords stay valid long after cookies expire. Rotate credentials regardless of a log's age.
Can someone search a stealer log database for my company? Listings advertise exactly that: search by domain or target, sometimes through a bot. That is why monitoring your own domains matters.
How can I check my exposure? Try the free exposure search in Cypho Signals, which shows counts, indexing dates and a masked preview, not raw credentials. Cypho's platform monitors the sources where logs are traded and alerts you when your domains appear. To see it in action, contact our team.