Researchers Link ArtHouse Cloud Logs Dump to 16,211 Stolen Credentials
HEROIC researchers linked a public Telegram upload from October 1, 2025, to active stealer malware campaigns targeting ArtHouse Cloud Logs users across the United States. The dataset contained 16,211 records, each structured as a credential triple: an email address, a plaintext password, and one or more associated URLs. The upload appeared on a channel that security researchers have been tracking as a distribution point for infostealer output, and the log format matched known families active in mid-2025. Our team cross-referenced the exposed records against our breach intelligence index and confirmed this dataset contains unique records not previously catalogued from earlier ArtHouse-related uploads.
Why This Is Dangerous
Sixteen thousand plaintext credential pairs give attackers an immediately actionable attack surface. Credential stuffing tools require no cracking step when passwords are already in the clear -- an attacker simply loads the file and starts testing logins against any platform they choose. The presence of API host URLs in each record is particularly useful for targeted attacks: it tells the attacker which cloud services, portals, and infrastructure endpoints the victim was actively authenticated to at the time of infection. This allows threat actors to prioritize high-value targets rather than wasting attempts on inactive accounts.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API host endpoints and accessed cloud services)
Why This Matters
Credential theft at this scale creates direct pathways to account takeover, financial fraud, and identity theft. Attackers who gain access to a victim's primary email account through credential stuffing can trigger password resets across every linked service -- banking, healthcare, insurance, and workplace systems. For enterprises, the risk is compounded: a single compromised employee credential can allow an attacker to establish a foothold inside a corporate network, move laterally, and deploy ransomware or exfiltrate intellectual property. The fact that this stealer log was distributed via a public Telegram channel means it was recieved by potentially thousands of subscribers before it was indexed by security researchers.
How Stealer Log Breaches Work
Infostealer malware is designed to harvest credentials from a victim's device as quietly as possible. It typically arrives via a phishing email attachment, a fake software installer, or a malicious browser extension. Once active, it scans every location where credentials might be stored: browser password vaults, saved autofill entries, desktop application configuration files, and session cookies. It captures not just usernames and passwords but also the URLs of the services where those credentials were used, which is why API host information appears alongside each record in this dataset. The collected data is sent to the attacker's infrastructure in real time or on a schedule, then organized into log files. Operators of large-scale stealer campaigns frequently seperate logs by geography or service type before distributing them on Telegram. Researchers tracking this campaign beleive the October 1 upload represents one node in a broader coordinated distribution effort targeting cloud service users in the United States.
Check If You Are Affected
Researchers link this dataset to ArtHouse Cloud Logs users whose credentials were active before October 2025. If you used this service, your email and password may be among the 16,211 exposed records. HEROIC monitors over 400 billion breached records and provides a free lookup at heroic.com. Check your email address now, update any reused passwords, and enable two-factor authentication on your primary accounts to reduce exposure from future credential stuffing campaigns.
Breach Breakdown
16,211 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds