ArtHouse Cloud Logs v2: 60,549 Passwords Now Circulating
Picture a criminal marketplace channel on Telegram, a fresh file dropped labeled "ArtHouse Cloud Logs NEW v2." In July 2026, HEROIC analysts caught this exact scenario: a follow-up release to an earlier ArtHouse Cloud Logs batch, containing 60,549 records, each pairing an email address with a plaintext password and the login URL the credential was captured from.
Why This Second ArtHouse Release Is Dangerous
A "v2" label means the operator behind ArtHouse is actively continuing to harvest and distribute data, and this batch is more than double the size of the first version HEROIC tracked. This information was not stolen from a company's servers. It was pulled directly from infected computers by information-stealing malware, which quietly copies saved browser passwords before sending them to whoever runs the operation. Because each record already pairs a specific website with a working email and password, an attacker can log straight in without any guesswork.
What Was Exposed
- Email addresses
- Plaintext passwords
- Login URLs (the exact site each credential unlocks)
Why This Matters
Because the passwords in this file are plaintext and already matched to their websites, they are immediately usable for credential stuffing and account takeover on a large scale. With over 60,000 records in this release alone, the risk of identity theft and financial fraud is real for anyone caught up in it, especially if a password has been reused across multiple accounts.
How Repeated Cloud Log Releases Like ArtHouse Happen
Stealer logs come from ongoing malware infections rather than a single database hack. Victims are infected through cracked software, phishing links, or fake downloads, and the malware continuously collects saved usernames, passwords, cookies, and autofill data from new victims. Operators package this growing pool of stolen data into versioned releases, like this v2 file, and share or sell them on Telegram channels and dark web forums as the count climbs.
Check If You Are Affected
With 60,549 credential pairs in this release, checking your exposure is worth the minute it takes. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one, so you can quickly find out if your email or passwords have been exposed and secure your accounts before someone else uses them.
Breach Breakdown
60,549 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds