40,281 Plaintext Passwords From ArtHouse Cloud Logs Surfaced on Telegram
HEROIC analysts detected a stealer log upload to a public Telegram channel on September 29, 2025, containing 40,281 records directly tied to the ArtHouse Cloud Logs service. What made this dataset stand out was not just the volume -- it was the composition. Every record contained a plaintext password alongside an email address and the URL of the service or API host the victim was accessing at the time of infection. No hashing, no encoding, no obfuscation. The credentials were fully readable and immediately usable by any threat actor who accessed the channel. Our team identified the upload through automated dark web monitoring and began processing the dataset for cross-referencing within the same session.
Why This Is Dangerous
Forty thousand plaintext credential records represent an attack package that requires zero technical preparation. Any actor with access to the Telegram channel could download the log and begin credential stuffing operations against email providers, banking portals, corporate VPNs, and SaaS platforms immediately. The API host URLs embedded in each record go a step further by mapping exactly which services each victim was authenticated to, effectively pre-sorting targets by value. This is not a theoretical risk -- credential stuffing operations using logs of this format have been linked to large-scale account takeovers within days of the initial Telegram post.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API host endpoints and accessed service records)
Why This Matters
A 40,000-record plaintext credential dump creates cascading risks for both individuals and organizations. At the individual level, anyone in this dataset whose password is reused across multiple accounts faces account takeover, unauthorized financial transactions, and identity theft. At the organizational level, compromised employee credentials from stealer logs are one of the leading initial access vectors for ransomware and data extortion attacks. The September 29 upload date means this data has been publicly available for weeks before many affected users will have any knowledge of the exposure. Early action -- checking your email, rotating passwords, and enabling two-factor authentication -- is the most effective way to reduce the risk window.
How Stealer Log Breaches Work
Infostealers are a category of malware specifically engineered to extract credentials from infected devices. They operate through several attack vectors: phishing campaigns distributing trojanized documents, fake software downloads on torrent and warez sites, and malicious browser extensions that disguise themselves as legitimate productivity tools. After installation, the malware quietly enumerates browser saved passwords, autofill databases, session cookies, and desktop application credential files. The full session context -- including the URL of the authenticated service -- is captured alongside each credential pair, which is why API host information appears in this dataset. Results are exfiltrated to a collection server, organized into structured log files, and then distributed. The ArtHouse Cloud Logs service appears across multiple stealer log uploads we have tracked through late September and early October 2025, suggesting the service's user base was a recurrent target of active infostealer campaigns during this period. We have also occured multiple log files from related channels using the same structural format, indicating coordinated distribution rather than isolated incidents.
Check If You Are Affected
40,281 plaintext passwords from ArtHouse Cloud Logs were posted to Telegram on September 29, 2025. If you used this service before that date, your credentials may be in this dataset. HEROIC's breach intelligence database contains over 400 billion records and provides a free, instant lookup by email address at heroic.com. If your email appears in this breach, change your password immediately on every account where you use the same credentials, revoke any active API tokens, and contact your IT security team if this account was connected to your workplace environment.
Breach Breakdown
40,281 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds