The bubop_cloud Stealer Log Put 37,791 Stolen Email and Password Pairs Online in June 2025
In June 2025, HEROIC's DarkHive threat intelligence analysts identified a stealer log uploaded to Telegram by a user known as bubop_cloud. The file contained 37,791 records of compromised credentials, with each entry holding an email address, a plaintext password, and the URL of the service where those credentials were harvested. The dump was posted publicly, meaning anyone on Telegram could download it and begin exploiting the stolen data with no technical skill requred.
The Danger of 37,791 Unencrypted Login Credentials
Plaintext passwords eliminate every obstacle an attacker would normaly face. There is no need to run password cracking software, no need to rent cloud computing power, and no need to spend hours or days waiting for results. Each credential in this bubop_cloud dump is immediately usable. An attacker can open a browser, navigate to the URL listed in the record, type in the email and password, and gain access to someone's account in seconds. When you multiply that across nearly 38,000 records, the potential for widespread damage is enormous.
What Was Exposed in the bubop_cloud Dump
- Email Addresses: Login emails for personal accounts, work platforms, and online services
- Plaintext Passwords: Raw, unprotected passwords captured directly from infected devices
- URLs: The exact web addresses where each credential was used, giving attackers a precise target list
Why Credential Reuse Makes This Breach Worse
Research consistently shows that most people reuse the same password across multiple accounts. This is exactly what attackers count on when they get hold of stealer log data like the bubop_cloud dump. They take one email and password pair and test it against dozens of popular services, from online banking and email providers to streaming platforms and shopping sites. One successful match can quickly spiral into full account takeover, financial fraud, and identity theft. The inclusion of URLs in this dataset tells criminals which services the victim already uses, making their attacks significently more targeted and effective.
How Infostealer Malware Builds These Logs
The bubop_cloud stealer log was created by infostealer malware running on victims' devices. This type of malware typically spreads through phishing emails, pirated software, or malicious browser extensions. Once installed, it operates in the background without any visible signs. The malware pulls saved passwords from web browsers, records login activity, and captures the URLs of every site the victim visits. All of this data gets compiled into a log file and sent to the attacker's infrastructure. From there, it enters the underground economy, where it is sold, traded, or given away on platforms like Telegram. By the time the victim notices anything wrong, their credentials may have already been shared with thousnads of criminals.
See If Your Data Appeared in This Leak
HEROIC's breach intelligence database indexes more than 400 billion records from stealer logs, data breaches, and dark web sources around the world. Our free breach scanner can check your email address against the bubop_cloud dump and thousands of other known leaks in seconds. If your credentials show up, take action immediately by changing your passwords and turning on two-factor authentication wherever possible. The sooner you know, the sooner you can protect yourself.
Breach Breakdown
37,791 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds