Breach Intelligence Report 29 Apr 2026

ArtHouse Cloud Logs: Creative Industry Breach Hits 60,244

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs ArtHouse CLoud Logs uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 60,244
Source Type Stealer log
Origin United States
Password Type plaintext

In December 2025, HEROIC analysts flagged a large-scale Telegram upload of the ArtHouse Cloud Logs stealer log dataset, exposing 60,244 records containing email addresses, plaintext passwords, and harvested login URLs. The ArtHouse branding of this dataset suggests the infostealer campaign was particularly focused on creative industry users -- individuals working in art, design, media, and entertainment sectors who rely heavily on cloud-hosted platforms for collaboration, portfolio management, and client work. With 60,244 exposed records, this is one of the larger single-batch stealer log releases in recent memory.

Creative professionals are an increasingly valued target for credential theft operations. Their accounts often provide access to high-value intellectual property, client databases, payment platforms like Adobe Commerce and Patreon, and creative cloud subscriptions. A compromised creative cloud account can result in theft of unreleased creative work, client data, and financial information. The sheer scale of this dataset -- over 60,000 records -- makes it a significant threat to anyone whose credentials may have been captured by the infostealer malware behind this campaigne.

Data Categories Leaked in the ArtHouse CLoud Logs Breach


  • Email Addresses - professional and personal identifiers linked to creative platform accounts
  • Plaintext Passwords - unencrypted credentials instantly usable for account takeover attacks
  • URLs - login endpoints for cloud services, creative platforms, and collaboration tools

Why ArtHouse CLoud Logs Puts Your Online Accounts at Risk


For creative industry victims in this dataset, the fraud chain carries unique professional and financial consequences. Compromised email accounts unlock password resets on creative subscription services such as Adobe Creative Cloud, Figma, and Canva, along with freelance platforms, client portals, and payment processors. Attackers who gain access to these accounts can steal unreleased creative work for resale, lock victims out of their own professional tools, access stored client payment data, and even impersonate the victim to commit fraud with their clients. The URLs included in this dataset reveal which platforms each victim actively uses, allowing attackers to systematically target the most valuable accounts first. Given that many creative professionals store original, non-replaceable work in cloud environments, the consequences of account compromise can extend far beyond simple financial loss.

Stealer log Attacks: How They Harvest Your Login Data


The ArtHouse Cloud Logs dataset was produced by infostealer malware that infected victims' devices and harvested credentials before the December 2025 Telegram upload. Infostealers targeting creative professionals commonly spread through fake font downloads, cracked design software, malicious Photoshop plugins, and phishing emails posing as design platform notifications. Once on a device, the malware silently extracts browser-saved passwords, cloud application tokens, and active session cookies. The harvested data is bundled into structured log files and distributed through Telegram channels where criminal buyers can immediately begin running credential stuffing attacks. Victims often have no idea their device was compromised untill they discover unauthorized logins or stolen work.

Free Scan: Check the ArtHouse CLoud Logs Breach Records


HEROIC's breach intelligence database now indexes over 400 billion exposed records, including large-scale stealer log datasets like ArtHouse Cloud Logs. Whether you work in design, media, or any other creative field, your accounts may be at risk if your credentials appear in this December 2025 breach. Run a free HEROIC scan today to check your exposure and enable real-time monitoring so you are alerted the instant your data appears in any new breach dataset.

Breach Breakdown

Domain ArtHouse CLoud Logs uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 29 Apr 2026
Check in 5 seconds

60,244 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,693 scanned today
Breach Rank #N/A by affected users
Impact Score
2
sensitivity + scale + recency
Est. Financial Impact $435.9K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance