ArtHouse Cloud Logs v3 Exposes 38,731 More US Accounts Now
The ArtHouse series kept growing on June 8, 2026, when a third file, ArtHouse CLoud Logs v3, appeared on Telegram with 38,731 more stolen credential records.
Why This Is Dangerous
Three releases in one day from the same source points to an active, ongoing operation rather than a one-time leak. Each password in this batch is stored in plain text with zero protection.
What Was Exposed
- Email addresses (38,731 unique accounts)
- Plaintext passwords with no encryption
- URLs tied to each compromised service
Why This Matters
With three ArtHouse files now public, totaling well over 100,000 combined records across v1, v2, and v3, this has quickly become one of the more significant stealer campaigns of the month. If you haven't checked your email against any of the earlier releases, this is a good time to look at all three.
How Stealer Logs Work
Operators running large stealer campaigns often release their haul in batches rather than all at once, partly to keep interest high and partly because new infections keep adding fresh data. Each new file, like this v3 release, typically contains credentials collected in the days seperating it from the last release.
Check If You Are Affected
HEROIC tracks more than 400 billion (400B+) exposed records, including every version of the ArtHouse Cloud Logs series. Use HEROIC's free scanner to check your email imediately against all three releases.
Breach Breakdown
38,731 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds