ARCEUSULP Stealer Log Leak Targets US Users: 649,394 Exposed
ARCEUSULP 90 716229 Stealer Log: 649,394 US Records Exposed
On 02-Jul-2026, HEROIC analysts identified a large stealer log file named "ARCEUSULP 90 716229" uploaded by a Telegram user in a channel dedicated to trading stolen credentials. The file contained 649,394 records tied to United States accounts, each pairing an email address with a plaintext password and the URL of the site the login was captured from, making this one of the larger US-focused stealer log dumps HEROIC has catalogued.
Why This Stealer Log Is Dangerous
A dump of this size concentrated on United States accounts means a huge number of American consumers now have a working login sitting in a file criminals can access instantly. Because each record already includes the exact site the credentials belong to, an attacker does not need to guess where a password works, and since the passwords were captured in plaintext, there is no encryption barrier standing between the data and a working login.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the sites the credentials were used on
Why This Matters
With nearly 650,000 records in a single file, attackers gain enough volume to run large-scale credential stuffing campaigns against US banking, email, and shopping platforms, testing each stolen login against other services to see where it also works. Anyone whose information appears in this file and who reuses passwords across accounts faces a real and immediate risk of account takeover and the identity theft that can follow.
How Stealer Logs Work
Stealer logs come from malware that infects a victim's device, often through a malicious download or infected file, and silently harvests saved browser logins, passwords, and the websites they belong to. That stolen data is compiled into a log file like this one and traded or sold through Telegram channels and dark web marketplaces, where attackers can buy access to hundreds of thousands of working credentials at once.
Check If You Are Affected
Given the scale of this leak, checking your exposure directly is the safest move. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including stealer logs like this one, so you can quickly find out if you were affected and change any passwords that are still at risk.
Breach Breakdown
649,394 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds