Dark Web Intel: ArtHouse Cloud Logs Breach Exposes 28,583 Records
HEROIC's dark web monitoring team flagged a new stealer log package known as "ArtHouse Cloud Logs" that surfaced on a Telegram channel in June 2026. The file holds 28,583 records, each one linking a website address to the email and plaintext password an infected user had saved for it. These credentials were not stolen from a company's servers. They were lifted directly off victims' own devices by malware running quietly in the background.
Why This Is Dangerous
Because the passwords sit in plain, unencrypted text, anyone who gets a copy of this log can use the credentials immediately. There is no cracking, no guessing, no delay. An attacker can open each URL, plug in the matching email and password, and be logged in within seconds. That immediacy is what makes stealer logs so valuable on dark web marketplaces and so risky for the people caught inside them.
What Was Exposed
- Email addresses
- Plaintext passwords
- Website URLs tied to each login
Why This Matters
Stealer logs like this one are a favorite tool for credential stuffing attacks, where automated bots test the same email and password combo across banking sites, email providers, and shopping accounts. If a person reused this password anywhere else, that single reused credential can open the door to account takeover, identity theft, and direct financial fraud.
How Stealer Log Malware Operates
Infostealer malware usually sneaks onto a device through pirated software, a fake browser update, or a phishing link. Once it's active, it scans the browser's saved password vault and autofill data, then quietly exfiltrates everything to a remote server controlled by the attacker. The resulting file, or "log," is bundled up and traded or given away on Telegram, where dark web intel researchers like HEROIC's team routinely intercept and analyze them.
Check If You Are Affected
HEROIC continuously tracks leaks like this one across its database of over 400 billion breached records. Use HEROIC's free breach scanner to check whether your email address, and the passwords tied to it, are circulating in this leak or any other before someone else finds them first.
Breach Breakdown
28,583 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds