cvv190_cloud_2 Stealer Log: 13,254 Records Leaked the Day After Two Other Breaches
HEROIC analysts flagged a stealer log file called cvv190_cloud_2 that surfaced on Telegram on March 11, 2026, just one day after the first two ArtHouse Cloud log files appeared. That timing matters. The cvv190_cloud_2 file contained 13,254 records, each one pairing a real email address with a plaintext password and the URL of the targeted service or API endpoint. At more than 13,000 records, this is the largest of the March 2026 Telegram stealer log releases tracked by HEROIC, and its proximity in time to the other uploads suggests coordinated or overlapping criminal activity during a very narrow window.
Why the Scale and Timing of cvv190_cloud_2 Makes It More Dangerous
A file this size does not appear overnight by accident. The name cvv190_cloud_2 suggests it is the second installment from this particular threat actor or operator, implying a first batch already exists. Thirteen thousand plaintext credentials hitting Telegram in a single upload means that a large number of people had their passwords exposed all at once, with no warning and no delay. Because the passwords are stored in plaintext, every single record is immediately actionable. There is no technical barrier between a cybercriminal downloading this file and walking into the accounts it describes.
What Was Exposed in the cvv190_cloud_2 Stealer Log
- Email Addresses: Full login identities usable as usernames across thousands of online services
- Plaintext Passwords: Unencrypted, ready-to-use passwords with no cracking required
- URLs: Specific web addresses and API endpoints revealing exactly which platforms and services were compromised
Why March 2026 Mattered: A Coordinated Wave of Stealer Log Releases
The cvv190_cloud_2 file did not appear in isolation. Within a two-day window in March 2026, at least three stealer log collections surfaced on Telegram, all tracked by HEROIC. Combined, those releases exposed more than 22,000 records. When multiple log files appear together in a short period, it often indicates that a criminal operation has completed a collection phase and is moving into the distribution phase. That distribution spreads the data widely and quickly, making it harder to contain. For each of the 13,254 people in cvv190_cloud_2, the risk of credential stuffing, account takeover, and identity theft rose sharply the moment that file went live.
How Stealer Logs Like cvv190_cloud_2 Are Created
The cvv190_cloud_2 log was not created by hacking a company database. Infostealer malware installed on individual users' devices did the actual data collecton. These programs run silently in the background, reading saved passwords from browsers, capturing active sessions, and recording which URLs the user visits. Each infected machine contributes a set of records to the operator's growing collection. The operator then bundles those records into a named file, in this case cvv190_cloud_2, and uploads it to Telegram for free distribution or sale. The victims rarely know their device was infected, and even more rarely know their credentials are now in criminal hands.
Check If Your Credentials Appeared in cvv190_cloud_2
With 13,254 exposed records, cvv190_cloud_2 is one of the more significant stealer log releases HEROIC tracked in early 2026. HEROIC's free breach scanner searches across more than 400 billion records, including this file and thousands of other stealer log collections. Enter your email at heroic.com to see in seconds whether your credentials were part of this March 2026 leak. It is free, takes no account setup, and could reveal exposure you had no way of knowing about.
Breach Breakdown
13,254 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds