ArtHouse Cloud Logs v2 Hit Telegram. The Data Went Live Instantly.
The ArtHouse Cloud Logs v2 stealer log showed up on a public Telegram channel on September 13, 2025. By the time most people heard about it, the data had already been circulating for hours. That gap matters. When 50,823 sets of credentials sit in a public channel even breifely, the window for damage is wide open before anyone has a chance to reset a password or lock down an account.
Why This Is Dangerous
This is not a case where a hashed password database leaked and attackers still had to crack it. ArtHouse Cloud Logs v2 contained plaintext passwords, meaning whoever downloaded the file got instant, ready-to-use credentials. No cracking tools, no GPU farms, no waiting. Combine that with the email addresses in the same file, and any attacker had a complete login package. With 50,823 records in one archive, even a low-skilled actor could automate account takeover attempts across dozens of services in minutes.
What Was Exposed
- Email addresses tied to real user accounts
- Plaintext passwords captured directly from infected endpoints
- URLs including API hosts and service endpoints
- 50,823 total records confirmed in the leaked archive
- Data structured as stealer log output, meaning it came from live sessions
Why This Matters
Stealer logs are not like typical database dumps where the attacker had to breach a server. In this case, malware was running on real peoples computers, capturing passwords as they typed them and sessions as they were active. That means the credentials were valid at the time of capture. Users who reuse passwords across services are especially at risk because a single compromised email and password pair can unlock accounts on banking apps, email providers, and social platforms. The September 13 upload date also means this data was fresh, not stale credentials from years ago.
How Stealer Log Works
Infostealer malware typically arrives through phishing emails, cracked software downloads, or malicious browser extensions. Once it installs on a device, it quietly records keystrokes, steals saved browser passwords, captures session cookies, and logs any credentials entered into forms. All of that data gets packaged into a log file and sent back to the attacker. The attacker then either uses the data directly or sells it on dark web markets and Telegram channels, sometimes within hours of the infection occuring. The v2 designation on this particular log suggests it was part of a series, meaning the same or related malware campaigns had been running for some time before this batch was published.
Check If You Are Affected
If you have ever used ArtHouse Cloud or any service whose credentials may have been captured by endpoint malware, your information could be in this dataset. The best way to find out is to check against a database that indexes breaches like this one.
Heroic.com has indexed over 400 billion records from data breaches and stealer logs worldwide. You can search your email address to see if it appears in the ArtHouse Cloud Logs v2 dataset or any other known breach. Visit heroic.com to run a free check and take steps to secure your accounts before someone else does.
Breach Breakdown
50,823 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds