US Accounts Hit as ArhontCorp Leaks 19,577 Credentials Now
United States accounts took another hit on June 9, 2026, when a file called Private CartelJohnDoe TG ArhontCorp- ScroogeUrl exposed 19,577 stolen credential records on Telegram.
Why This Is Dangerous
This is at least the second ArhontCorp branded ScroogeUrl file to surface recently, suggesting the underlying malware operation is still actively targeting accounts across the country.
What Was Exposed
- Email addresses (19,577 unique accounts)
- Plaintext passwords with no encryption
- URLs tied to each compromised service
Why This Matters
With US accounts specifically in the crosshairs again, this file adds to a growing pile of ArhontCorp related leaks. If you checked an earlier ArhontCorp file and came up clear, it's worth checking again here, since new batches keep surfacing.
How Stealer Logs Work
The 'CartelJohnDoe' and 'Private' labels in the filename suggest this data was shared within smaller criminal circles before this public Telegram release. Stealer malware behind operations like this typically infects devices through cracked software, then quietly harvests every saved password before shipping the data back to whoever is running the campaign, wich eventually leads to a public dump like this one.
Check If You Are Affected
HEROIC's free scanner checks your email against more than 400 billion (400B+) leaked records, including every ArhontCorp related file on record. Run the check now, and don't asume you're clear just because an earlier ArhontCorp check came back empty.
Breach Breakdown
19,577 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds