ArtHouse Cloud Logs v1 Exposed 117,009 Plaintext Passwords
ArtHouse Cloud Logs v1 leaked 117,009 email and password pairs on June 1, 2026. Every password was stored in plaintext. Every record included the exact site it unlocked.
Why This Is Dangerous
Plaintext means readable. No hashing, no encryption standing between the stolen data and whoever opens the file. A leak of 117,009 records in this format hands over working logins immediately, with no cracking or guesswork required on the attacker's end.
What Was Exposed
- 117,009 email addresses harvested from infected devices
- Plaintext passwords matched one to one with each address
- The login URLs tied to every credential pair
Why This Matters
A leak this size doesn't stay contained to one group of people or one region. It touches personal accounts, work logins, and shared family services all at once. Anyone who relizes their email might be part of the 117,009 needs to treat every password tied to that address as already known to someone else.
How Stealer Logs Work
This is the first version in what appears to be an ongoing ArtHouse Cloud series, meaning the group behind it collects stolen credentials continuously and releases them in numbered batches. The underlying method stays consistent: malware installed through a deceptive download quietly reads saved browser passwords, then exports them into a file exactly like this one before it's shared further.
Check If You Are Affected
HEROIC's free scanner checks your email against more than 400 billion leaked records, including this one. It takes under a minute, and given the size of this particular leak, it's definately worth doing today rather than assuming you're one of the lucky ones.
Breach Breakdown
117,009 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds