10,694 US Accounts Exposed: ArtHouse Cloud September 7 Dump
On September 7th, 2025, a Telegram user uploaded a stealer log file to a public channel that contained credentials harvested from infected machines across the United States. The log was attributed to an account known as "ArtHouse CLoud" and included 10,694 records pulled straight from compromised endpoints. What makes this incident worth examining is not just the size of the dump, but what was inside: unencrypted passwords sitting right next to email adresses and API hostnames, ready for immediate misuse. This is what modern credential theft looks like when it lands in the open.
Why This Is Dangerous
Stealer log files like this one are not just a list of passwords. They are a snapshot of active sessions, saved logins, and browser-stored credentials taken directly from a real person's machine at the moment of infection. The plaintext password format means there is no cracking required -- attackers can try these credentials immediately across email providers, banking apps, corporate VPNs, and cloud platforms. With 10,694 records in circulation on Telegram, anyone who downloaded the file had instant access to a working credential list tied to real US-based users and cloud service endpoints.
What Was Exposed
- 10,694 records total from the stealer log file
- Email addresses for each compromised user
- Plaintext passwords -- no hashing, no encryption, usable as-is
- URLs showing which sites and services were accessed at time of infection
- API hostnames revealing cloud or backend service endpoints tied to the accounts
- Endpoint data indicating the devices from which credentials were harvested
Why This Matters
The United States remains the most targeted country for infostealer malware campaigns, and leaks like this one show why. Cloud service credentials and API access details are especially valuable because they don't just compromise a single account -- they can open doors into entire organizations. An attacker who finds your work email, your plaintext password, and the URL of your company's internal portal in one log file has everything needed to walk right in. For individuals, the risk of account takeover is immidiate. For businesses whose employee credentials appear in these logs, the exposure is much broader.
How Stealer Log Works
A stealer log is the output file generated by credential-stealing malware after it has run on a victim's machine. These malware families -- sometimes called infostealers -- silently install on a computer through phishing emails, fake software downloads, or malicious browser extensions. Once active, they scrape saved passwords from browsers, capture keystrokes, harvest session cookies, and record active login URLs. The resulting log file is then sent back to the attacker and often sold or shared on Telegram channels and underground forums. The entire process can take minutes and leaves no obvious trace for the average user to notice.
Check If You Are Affected
If your email address or password appeared in the ArtHouse CLoud Logs stealer dump, you may not know until an attacker has already used that access. The best way to find out is to search our breach database at heroic.com, where we index over 400 billion leaked records including stealer log data. Enter your email to see if your credentials have been exposed -- and if they have, change your passwords immediately and enable two-factor authentication on every account that matters to you.
Breach Breakdown
10,694 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds