The Cloud_Rolex_2 Dump Contains Exactly 1,905 Email and Password Pairs
On January 20, 2026, a Telegram user uploaded a stealer log file labeled Cloud_Rolex_2 to a public channel, making it freely accessible to anyone who wanted it. The file contained exactly 1,905 records, each consisting of an email address, a plaintext password, and one or more associated URLs and API hostnames. Not a round number. Not an estimate. Exactly 1,905 real people's credentials, harvested one by one from their own devices by infostealer malware and then posted publicly. The precision of that number is itself a signal: these logs are methodicaly compiled by automated malware running on compromised machines, bundling everything it finds before sending it home to whoever deployed it.
Why This Is Dangerous
Plaintext passwords require no decryption. The moment this log was posted to Telegram, every one of those 1,905 credential pairs became immediately usable. Attackers do not need to invest time or compute power cracking hashes -- they simply take each email-password combination and begin testing it against banks, email providers, social media platforms, and corporate login portals. The API hostnames included in the log take the risk further: they reveal exactly which services and integrations those victims were authenticating against, allowing attackers to surgically target the most valuable accounts rather than spraying credentials at randum services.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs and API Hosts (identifying connected services and applications)
Why This Matters
January 2026 is recent. The Cloud_Rolex_2 log is not a relic from years ago -- it was posted within the last few months, and the credentials it contains may still be active on sites where victims have not yet changed their passwords. For anyone who reuses the same password across multiple accounts, a single exposure in this log could unlock email inboxes, cloud storage, financial accounts, and workplace systems. The presence of API host data also puts businesses at risk: if a developer or employee's credentials to an internal tool or third-party integration were captured, the consequences extend far beyond one person's personal accounts.
How Stealer Logs Work
Infostealer malware is installed on a victim's device without their knowledge, commonly through a phishing email attachment, a fake software crack, or a malicious browser extension. Once active, it silently scans the device for saved passwords, browser cookies, session tokens, and API keys stored in configuration files. Everything it finds is copied into a structured log file and transmitted to an attacker-controlled server. The attacker then assembles these individual logs into compilations, sometimes selling them and sometimes -- as with Cloud_Rolex_2 -- posting them publicly on Telegram where any threat actor can download and use them. The whole cycle from initial infection to public distribution can complete in a matter of days, leaving victms almost no time to react.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion exposed records, including stealer logs like Cloud_Rolex_2, to determine whether your email address or passwords have been compromised. Given how recently this log was posted, running a scan now is especially important. Check your exposure for free and find out what steps to take if your credentials appeared in this or any other leak.
Breach Breakdown
1,905 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds