ArtHouse Cloud Users Are Now Exposed: 13,811 Stolen Logins Surface
HEROIC analysts identified a stealer log titled "ArtHouse Cloud logs v2," uploaded to a Telegram channel on August 2, 2026. The file contains 13,811 records made up of endpoints, email addresses, API hosts, and plaintext passwords.
Why This Is Dangerous
Because this data comes from a stealer log rather than an old database, the credentials inside were likely still in active use at the time they were captured. Each record ties a password directly to the endpoint or service it unlocks, giving an attacker a ready-made path into a working account.
What Was Exposed
- Email addresses
- Plaintext passwords
- Endpoint and API host URLs
Why This Matters
Stealer log data tends to be fresher and more accurate than older leaked databases, since it is pulled directly from infected devices rather than recycled breach files. That freshness makes it especially useful to attackers running account takeover and credential stuffing attempts, since the logins are more likely to still work.
How Stealer Logs Work
Stealer malware infects a device, often through a fake download or pirated software, then collects saved browser passwords, cookies, and autofill fields before sending the haul back to whoever controls the malware. That data is bundled into a "log" and posted or sold, frequently within days of the infection.
Check If You Are Affected
HEROIC's database holds more than 400 billion records pulled from stealer logs, combolists, and confirmed breaches. Run a free scan to check if your email or credentials appear in this ArtHouse Cloud logs v2 file or any other exposure, and get clear next steps to secure your accounts.
Breach Breakdown
13,811 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds