Breach Intelligence Report 01 Nov 2025

ArtHouse Cloud Logs MacOs v1 uploaded by a Telegram User

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 235,529
Source Type Stealer log
Origin Telegram
Password Type plaintext

235,529 credential records from macOS devices hit a public Telegram channel on August 8, 2025. The file was labeled ArtHouse Cloud Logs MacOs v1, and it was not a small or generic dump. It was specifically generated by infostealer malware targeting Apple devices, which made it notable in a threat landscape that still tends to underestimate Mac-focused attacks. Every record in the file included an email address, a plaintext password, and the URL where that password was being used, pulled directly from compromised macOS endpoints.

Why This Is Dangerous


macOS users are often told their devices are more secure than Windows machines, and that perception leads to relaxed security habits. This leak challenges that directly. The ArtHouse Cloud Logs MacOs v1 file proves that infostealers are actively and successfully targeting Apple devices at scale. With 235,529 records and plaintext passwords throughout, this is exactly the kind of data that fuels credential stuffing campaigns, account takeovers, and deeper infrastructure compramise through the included API host information. The macOS-specific nature of this log suggests a targeted campaign rather than a broad spray-and-pray operation.

What Was Exposed


  • 235,529 total records harvested from compromised macOS endpoints
  • Email addresses for each affected account
  • Plaintext passwords requiring no further processing to use
  • URLs identifying the exact services and sites targeted per credential
  • API host information linking to backend and cloud service access points
  • Endpoint metadata from the infected Apple devices

Why This Matters


The scale here is significant. At over 235,000 records, this is one of the larger macOS-specific stealer logs to have surfaced publicly. The inclusion of API host data alongside credentials is particuarly worrying for organisations whose employees use Macs. Developer machines, creative workstations, and executive laptops running macOS are common in certain industries, and those devices often have access to sensitive systems and cloud environments. If any of the compromised users had admin access or developer credentials stored on their machines, the blast radius from this log goes well beyond individual account takeovers.

How Stealer Logs Work


macOS-targeting infostealers have grown significantly more sophisicated in recent years. They are typically delivered through fake application installers, cracked software distributed on torrent sites, or phishing messages with malicious attachments designed to look like legitimate tools. Once running on an Apple device, the malware accesses the macOS Keychain, browser saved passwords, and stored credentials in applications like Slack, Notion, or cloud sync tools. All of that data gets compiled into a structured log and exfiltrated to a remote server. The operator then packages the logs and posts them to Telegram channels, exactly as happened with ArtHouse Cloud Logs MacOs v1 in August 2025.

Check If You Are Affected


235,529 records is a lot of people. If you use a Mac and store passwords in your browser or in apps, your credentials may have been in this file. Heroic.com has indexed over 400 billion leaked records from breaches and stealer logs around the world, including this one. Search your email address for free right now to find out if your data has been exposed, which breaches it appeared in, and what you need to do next to secure your accounts.

Search 400B+ leaked records at Heroic.com

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 01 Nov 2025
Check in 5 seconds

235,529 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,733 scanned today
Breach Rank #2,774 by affected users
Impact Score
9
sensitivity + scale + recency
Est. Financial Impact $1.7M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance