The Cloud_Rolex_2 Dump: 45,085 Stolen Credentials Hit Telegram
HEROIC analysts flagged a stealer log upload on a public Telegram channel on May 29, 2025. The file, posted by an unidentified Telegram user under the label Cloud_Rolex_2, contained 45,085 records pulled directly from compromised endpoints. The exposed data included email adresses, plaintext passwords, and API host URLs, making this one of the more complete credential dumps identified from that period.
Why This Is Dangerous
Plaintext passwords require zero cracking effort. An attacker who gets this file can log into email accounts, business platforms, and cloud services immediately. The API host URLs included in the dump reveal exactly which services the victims were accessing, giving attackers a roadmap for follow-on attacks. With email access comes password reset capabilty for banking, payroll, and every other account tied to that inbox.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API hosts and service endpoints)
Why This Matters
When passwords are stored in plain text and then stolen, there is no buffer between the attacker and full account access. Victims of this breach face credential stuffing across every site where they reuse their password, account takeover on email and cloud services, and potential identity theft if personal details are linked to those accounts. Businesses whose employee credentials appeared in this log face unauthorized access to internal systems, data exfiltration, and possible ransomware deployment via compromised remote access tools.
How Stealer Logs Work
A stealer log is a file produced by information-stealing malware running on an infected device. Once installed, often through a phishing email or a fake software download, the malware silently copies saved passwords from browsers, email clients, and apps. It also records the URLs associated with each saved credential so attackers know exactly where those passwords are used. The resulting log file is then sent back to the attacker and frequently posted or sold on Telegram channels and dark web forums. The victim typically has no idea any of this has happened until accounts start getting accessed.
Check If You Are Affected
HEROIC's free identity scanner searches more than 400 billion exposed records, including stealer log data like this. Enter your email address to see whether your credentials appeared in the Cloud_Rolex_2 dump or any other known breach. Early detection gives you time to change passwords and secure accounts before an attacker acts on the data.
Breach Breakdown
45,085 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds