-
A threat actor reportedly offered 500 Lumma Stealer logs linked to systems in Poland.
-
The seller claimed the logs were collected within the previous 72 hours and remained valid.
-
The advertised data allegedly included passwords, cookies, crypto wallet details, and browser autofill information.

A threat actor is reportedly offering 500 Lumma Stealer logs allegedly taken from systems in Poland. The seller reportedly posted the logs on an underground marketplace.
The listing claimed the data was collected within the previous 72 hours. That claim suggests the seller wanted buyers to see the logs as fresh. However, the listing’s authenticity remains unconfirmed.
The advertised systems reportedly ran Windows 11 Pro 23H2. A sample also showed Brave Browser among the software installed on one affected computer.
The seller claimed the logs contained several types of sensitive information. These allegedly included stolen login details, browser cookies, crypto wallet data, and autofill information.
What the Alleged Logs Contain
The information in the listing matches several known capabilities of Lumma Stealer. Microsoft describes Lumma as malware that can steal data from infected Windows devices. The company says the malware can target browser passwords, session cookies, and autofill data. It can also search for crypto wallet files and browser extensions.
Microsoft also lists Brave Browser among browsers that security teams can monitor for suspicious access to sensitive data. Lumma operates through a malware-as-a-service model, according to Microsoft’s analysis. This model allows threat actors to use the malware for information theft without building the malware themselves.
The malware has also continued to attract attention after major disruption efforts. In February 2026, Ars Technica reported that Lumma had returned to large-scale activity. The report said attackers were using fake CAPTCHA pages and other tricks to help spread the malware.
The report explained that Lumma can collect browser credentials, cookies, financial information, secret keys, and crypto wallet data. The alleged Polish listing shows why criminals may value fresh infostealer logs.
Such logs can contain information taken directly from infected computers. The seller’s claims about the 500 logs have not been independently confirmed. The available information also does not confirm which victims supplied the data.
Why Stolen Logs Matter
Infostealer logs can contain more than simple usernames and passwords. Microsoft says Lumma can collect saved browser passwords, session cookies, autofill information, and crypto wallet data. The malware can also target information from other applications and user files. This means one infected computer may provide attackers with several types of useful information.
Stolen browser data can expose saved login details. Session cookies can also contain information linked to active online accounts. Crypto wallet information may also create risks for users who store wallet data on infected devices.
Microsoft says Lumma searches for wallet files, browser extensions, and local keys linked to several crypto services. The wider infostealer problem has also grown in recent years.
IT Pro reported in March 2025 that researchers had linked infostealers to millions of infected machines worldwide. The report cited KELA research that identified more than 4.3 million infected machines during 2024. In response to the growing threat, the EU has sanctioned Lumma Stealer developers and the cybercrime networks that profit from these infections.
The same report said Lumma accounted for 40.48% of infected machines in KELA’s data. It also said stolen credentials from infostealer logs can become a starting point for later attacks.
Another IT Pro report, citing Verizon’s 2025 Data Breach Investigations Report, said more than half of ransomware victims had credentials previously exposed through infostealers. These findings show why criminals continue to trade stolen logs. The data can provide access to accounts, personal details, and other information.
What Users and Organizations Should Do
Users should treat a possible Lumma infection as a serious security problem. Organizations should check whether employee credentials appear in exposed data. They should also require multifactor authentication wherever possible.
Security teams should review unusual login activity and investigate signs of stolen browser sessions. Changing a password alone may not address every risk linked to compromised session data.
Microsoft recommends keeping operating systems and antivirus products updated. The company also advises users to take steps that can reduce the chance of malware infection. Users should also avoid suspicious websites and unexpected downloads.
Ars Technica reported that recent Lumma campaigns used fake CAPTCHA pages to trick people into running malicious commands themselves.
The alleged sale of 500 Polish logs remains an unconfirmed marketplace claim. Still, the listing highlights the underground demand for fresh data stolen by infostealer malware.
Lumma Stealer remains capable of collecting valuable information from infected Windows devices. Microsoft and other security researchers continue to track its activity and capabilities.