Breach Intelligence Report 21 Apr 2026

HEROIC Found CLOUDHEAVENLOGS G-Country on Private Telegram Channels

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs G COUNTRY - 152PCS - CLOUDHEAVENLOGS uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,183
Source Type Stealer log
Origin United States
Password Type plaintext

On June 7, 2023, HEROIC's DarkHive monitoring system detected the CLOUDHEAVENLOGS G-Country pack being distributed across private Telegram channels -- 152 individual stealer log files bundled together and made available to buyers within hours of posting. This was one of at least seven regional packs released by the same operator on the same day, part of a coordinated multi-region distribution event that exposed thousands of stolen credentials across multiple geographic zones. The G-Country pack contained 2,183 compromised records, each one pulled from an infected device by infostealer malware before being sorted, labeled, and sold. HEROIC indexed the entire bundle upon detection.


Why This Is Dangerous

Telegram-based credential markets move fast. A pack like the CLOUDHEAVENLOGS G-Country bundle can be purchased, downloaded, and weaponized within the same day it appears on a private channel. Buyers of these packs run automated credential stuffing tools that test stolen email and password combinations across banking platforms, email providers, social media, and e-commerce sites simultaneosly. Because all passwords in this bundle are plaintext, there is no cracking step. The window between the initial Telegram post and the first unauthorized login attempt can be measured in hours, not days. The people whose credentials appear in this pack likely did not know they were at risk.


What Was Exposed

  • Email Addresses: 2,183 email addresses harvested from 152 infected devices in the G-Country geographic zone by infostealer malware running silently in the background
  • Plaintext Passwords: Unencrypted passwords extracted directly from browser saved-credential stores -- no decryption required by the buyer
  • URLs: Login page endpoints from each infected device, revealing exactly which services and accounts were in the browser at the time of infection

Why This Matters

The G-Country pack is part of a seven-region series released by CLOUDHEAVENLOGS on a single day -- a scale of operation that signals an industrialized credential distribution pipeline rather than a one-off breach. With 152 files and 2,183 records, the G-Country bundle sits in the middle of the day's releases by size -- larger than the F-Country 63PCS pack and smaller than the D-Country 425PCS drop. Private Telegram channels like the one hosting these packs are monitored by threat actors who recieve alerts the moment new credential bundles are posted, meaning exploitation begins almost imediately after publication.


How Stealer Log Distribution Works

CLOUDHEAVENLOGS operates as a credential aggregator and distributor. Affiliated malware operators deploy infostealers -- malicious software installed on victim devices through phishing emails, fake browser extensions, cracked software, and trojanized downloads. Each infected device generates a log file containing the browser's saved passwords, active session tokens, and form autocomplete data. CLOUDHEAVENLOGS collects those logs from affiliated campaigns, extracts geographic metadata to sort them by country or region, and packages the sorted files into branded bundles with alphanumeric labels like G-Country 152PCS. The finished bundles are then posted to private Telegram channels where buyers can purchase and download them within hours.


Check If You Are Affected

HEROIC's free breach scanner indexes more than 400 billion compromised records, including the full CLOUDHEAVENLOGS G-Country 152PCS bundle and every regional pack from the June 7, 2023 distribution event. HEROIC analysts monitor private Telegram credential channels continuously so new breaches are indexed as soon as they appear. Enter your email address to run a free instant scan and find out whether your credentials are in this pack or any of the thousands of other infostealer distributions in HEROIC's database.

Breach Breakdown

Domain G COUNTRY - 152PCS - CLOUDHEAVENLOGS uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 21 Apr 2026
Check in 5 seconds

2,183 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,148 scanned today
Breach Rank #26,901 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $15.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance