ICELOGSCLOUD 23 August: 11,610 U.S. Stealer Log Credentials (Aug 2022)
The Real Beginning: ICELOGSCLOUD's August 23 Release
New evidence from the ICELOGSCLOUD series pushes the channel's documented activity back further than previously known. The "23 AUGUST - 567 PCS ICELOGSCLOUD" bundle, uploaded August 23, 2022, predates the previously identified August 26 release, making it the earliest traceble entry in the channel's documented history. This earlier release also had higher volume -- 567 individual log files containing 11,610 U.S. infostealer credential records, compared to August 26's 554 pieces and 7,353 records. The August 23 release established the catagory-defining naming convention and set the template for the month-long run of date-stamped credential distribution that followed.
ICELOGSCLOUD August 23, 2022: Breach Summary
- Records Exposed: 11,610
- Data Types: Email addresses, plaintext passwords, target login URLs
- Breach Type: Infostealer malware log
- Country Affected: United States
- Date Leaked: August 23, 2022
The Full ICELOGSCLOUD Timeline
With the August 23 release confirmed, the complete known ICELOGSCLOUD series spans at least five documented releases: 23 AUGUST - 567 PCS (11,610 records), 26 AUGUST - 554 PCS (7,353 records), 6 SEPTEMBER - 778 PCS (38,655 records), 21 SEPTEMBER - 371 PCS (4,303 records), and 29 SEPTEMBER - 182 PCS (2,166 records). Together these five releases account for over 64,000 U.S. credential records distributed across approximately five weeks. The channel's activity peaked in early September and declined through the rest of the month -- a pattern consistent with malware campaign cycles where an initial infection wave yields high early volume that tapers as detection and cleanup reduce the infected device pool.
567 Pieces: August's Largest ICELOGSCLOUD Bundle
At 567 individual log files and 11,610 records, the August 23 release averaged roughly 20 credential pairs per infected device -- higher than the August 26 bundle's average of 13. This variation in per-device yield reflects the natural diversity of infostealer victims: some devices have extensively saved browser credentials across dozens of accounts, while others may have only a handful. Buyers working through the 567 files would find a mix of high-yield and lower-yield victims, with undiscoverd high-value targets among devices belonging to individuals with corporate email access, financial platform logins, or other sensitive accounts saved to their browsers.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including all known ICELOGSCLOUD series releases -- to tell you instantly if your email address or passwords have been compromised. Run a free scan today at HEROIC.com.
Breach Breakdown
11,610 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds