Check Now: cvv190_cloud_2 Stealer Leak Exposed 13,565 Records
A file named "cvv190_cloud_2" surfaced on Telegram on May 14, 2026, carrying 13,565 records of stolen login data. The name alone suggests the uploader was cycling through multiple batches of stealer logs, and this particular one is now sitting in the open for anyone to download.
Why This Is Dangerous
There's no way to garuntee that a file like this stays contained to one small circle of criminals. Once it's posted publicly, copies spread fast, and within days the same 13,565 records can end up scattered across multiple forums and resale channels.
What Was Exposed
- Email addresses tied to each compromised login
- Plaintext passwords with no encryption whatsoever
- The specific URLs where each set of credentials was captured
Why This Matters
Attackers don't need much to cause damage here. All the neccessary pieces, the email, the password, and the site it belongs to, are bundled together in one convenient package, which means someone can attempt account takeover almost immediately after downloading the file.
How Stealer Logs Work
This kind of file is built by malware that silently copies whatever a browser has saved, including autofill passwords and active session details, then exports it as a text log. The file naming pattern here suggests it's part of an ongoing series being uploaded in stages.
Check If You Are Affected
Don't wait to find out the hard way. Run your email through HEROIC's free scanner, which cross references more than 400 billion leaked records, including stealer log dumps like this one, and get a direct answer about whether your information was part of this leak.
Breach Breakdown
13,565 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds