ArtHouse Cloud Logs: 31,413 Passwords Found on Dark Web
On June 15, 2026, HEROIC analysts uncovered a stealer log known as ArtHouse Cloud Logs shared on a Telegram channel. The file held 31,413 records, each containing an email address, a plaintext password, and the URL of the login page it belonged to.
Why This Is Dangerous
These credentials were not stolen from a company database. They were pulled directly off infected computers by malware, meaning the passwords are stored exactly as the victims typed them. There is no encryption standing between an attacker and full account access.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the affected login pages
Why This Matters
With more than 31,000 credential pairs in circulation, the risk extends well beyond the original sites. Attackers routinely test leaked email and password combinations against other popular platforms through credential stuffing, which can quickly escalate into account takeover, identity theft, and financial fraud.
How Stealer Log Leaks Happen
Info-stealing malware typically arrives disguised as a cracked program, game cheat, or fake software update. Once it runs, it scans the browser for saved logins and cookies, then compiles the stolen data into a single log file. That file eventually surfaces on Telegram, exactly as it did with ArtHouse Cloud Logs.
Check If You Are Affected
There is a simple way to find out if you were caught up in this leak: run your email through HEROIC's free breach scanner and search a database of over 400 billion compromised records in seconds.
Breach Breakdown
31,413 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds