ArtHouse Cloud Logs Breach: 50,664 Passwords Exposed Online
HEROIC analysts uncovered a large stealer log named ArtHouse Cloud Logs v1, uploaded to a Telegram channel by an anonymous user in January 2026. The file contained 50,664 records, each pairing an email address with a plaintext password and the exact URL the login was used on.
What Kind of Breach Is This
This incident falls into a category security researchers call a stealer log breach. Unlike a company being hacked directly, a stealer log breach happens when malware on an individual's device secretly copies saved usernames and passwords over time. Those stolen credentials are then bundled together and sold or shared, often without the affected companies ever knowing their users' accounts were compromised.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (the exact login pages tied to each credential)
Why This Matters
With over 50,000 plaintext passwords already matched to specific websites, this log gives attackers everything needed for immediate credential stuffing attempts. Anyone who reused a password across multiple accounts is at heightened risk of account takeover, identity theft, and financial fraud, since a single working login can unlock several other accounts belonging to the same person.
How Stealer Log Breaches Actually Happen
It typically starts with a piece of infostealer malware disguised as a cracked game, pirated software, or a fake browser update. Once a victim installs it, the malware runs quietly in the background, reading through the browser's saved passwords, autofill history, and active session cookies. Everything it finds gets packaged into a single log file. That log is then uploaded to Telegram channels or dark web forums, where it is bought, sold, or in some cases given away entirely for free. Because the data reflects real, working sessions rather than old leaked databases, stealer logs are often considered more valueable to criminals than a typical breach dump.
Check If You Are Affected
With over 50,000 records circulating from this single log, checking your exposure only takes a moment. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs sourced from Telegram, so you can find out immediately if your credentials were caught up in ArtHouse Cloud Logs v1.
Breach Breakdown
50,664 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds