Researchers Link Bugatti Cloud Stealer Log to 16,495 Stolen Logins
HEROIC researchers identified a stealer log file called Bugatti_Cloud Bugatti_Man 30.07.part06, uploaded by a Telegram user in July 2026 as part of a larger series of split log files. This particular part contains 16,495 records pulled from malware infected devices, including endpoint URLs, email addresses, and plaintext passwords. Why this is dangerous: because stealer logs are captured directly from a victim's own device while they are actively logging into accounts, the credentials tend to be current and working rather than old or already changed. With passwords stored in plaintext, anyone who obtains this file can log into the affected accounts immediately, without needing to crack or guess anything. What was exposed: endpoint URLs showing which sites and services were accessed, email addresses, and plaintext passwords tied to each login. Why this matters: researchers commonly see stealer logs like this one traded in bulk because fresh, working credentials are more valuable to criminals than outdated leaks. Anyone among the 16,495 records in this file faces a real risk of account takeover, financial fraud, or identity theft if the same login is reused across other services. How stealer logs work: a stealer log is produced by information stealing malware that infects a device, often through a malicious download, cracked software, or a phishing link, then quietly harvests saved passwords and browser session data. The stolen data is sent back to the attacker, who splits large hauls into numbered parts, like part06 of this Bugatti Cloud series, before distributing the files through Telegram channels and dark web marketplaces. Check if you are affected: HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including stealer logs like this one. Run a free scan to see if your credentials appear among the 16,495 exposed records and get guidance on securing any account tied to a compromised password.
Breach Breakdown
16,495 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds