ArtHouse Cloud Logs v2 Holds More Stolen Credentials Than Most Towns Have Residents
HEROIC analysts flagged a stealer log file uploaded to a public Telegram channel on September 27, 2025, identified as ArtHouse Cloud Logs v2. The dataset contained 2,663 records, each one representing a real person's compromised endpoint at the exact moment a piece of malware was draining their credentials. Unlike a hacked database where passwords are typically hashed, this file delivered email addresses, plaintext passwords, and the specific API host URLs the victims were accessing when their machines were infected. The breadth of exposed endpoint data in this second version of the ArtHouse log series points to a sustained, ongoing credential harvestting operation rather than a one-time event.
Why This Is Dangerous
The danger in ArtHouse Cloud Logs v2 is not abstract. Every one of the 2,663 records represents a working email and password combination that can be tested against other services right now. Attackers who obtain this file do not need technical sophistication. They load the credentials into automated tools and run them against popular platforms: webmail, banking apps, corporate VPNs, cloud storage, and social media. The API host URLs included in each record make it even worse, because they tell an attacker exactly which services and environments were being accessed, allowing them to prioritize their attacks against the most valuable targets. This kind of targeted credential abuse is fast, quiet, and extremly hard to detect until real damage has been done.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API host endpoints captured at time of malware infection)
Why This Matters
When plaintext passwords leak alongside email addresses, the consequences extend far beyond the single service that was compromised. Most people reuse passwords across multiple accounts. Attackers know this and exploit it through credential stuffing, a technique where stolen credentials from one breach are systematically tested against hundreds of other services. The 2,663 records in ArtHouse Cloud Logs v2 can fuel account takeovers on banking platforms, corporate email systems, and health portals. Victims may experience identity theft, fraudulent financial transactions, unauthorized changes to their accounts, and in worst-case scenarios, their compromised credentials may be used as an entry point into the organization they work for. The API URLs in this dataset suggest some victims were accessing internal or cloud-based business tools, raising the specter of corporate data breaches driven by a single stolen password.
How Stealer Log Breaches Work
Stealer malware operates silently in the background of an infected machine. It is typically delivered through phishing emails with malicious attachments, fake software downloads, or compromised websites that exploit browser vulnerabilities. Once installed, the malware scans for saved browser passwords, session cookies, clipboard data, and active login credentials. It packages all of this into a structured log file and transmits it to a command-and-control server or directly to a Telegram channel operated by the threat actor. The victim rarely notices anything wrong. The ArtHouse log series, of which v2 is a continuation, follows this exect pattern: credentials captured live from real user sessions, then packaged and distributed through public Telegram channels for other threat actors to exploit. These files circulate widely once published, making it nearly impossible to contain their spread.
Check If You Are Affected
The 2,663 records from ArtHouse Cloud Logs v2 are now in circulation among threat actors. If your email address appears in this dataset, your passwords and the services you access may already be known to attackers. HEROIC maintains a continuously updated database of over 400 billion exposed records from breaches around the world. You can search your email address right now at heroic.com to find out if your credentials have been exposed. Change any affected passwords immediately, do not reuse them across other services, and turn on multi-factor authentication wherever possible.
Breach Breakdown
2,663 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds