Breach Intelligence Report 01 Apr 2026

DAISY_CLOUD February 25: 90 Infected Devices, 1,174 U.S. Credentials Stolen

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 1,174
Source Type Stealer log
Origin Telegram
Password Type plaintext

DAISY_CLOUD February 25: Another Day, Another Batch of Stolen Credentials

DAISY_CLOUD releases stealer logs in daily batches, each labeled with a date and a piece count. The February 25 release, labeled "90 PCS," came from 90 compromised devices and contained 1,174 U.S. credential records. The following day's batch had 103 devices. The pattern is systematic: infostealer malware runs continuously across a fleet of infected machines, and the operator uploads fresh batches to Telegram on a near-daily schedule.

HEROIC's DarkHive team confirmed the February 25 dataset: email addresses, plaintext passwords, and target login URLs, all from U.S. accounts, all from real people who had no idea their credentials were being packaged up and sent to Telegram.


What 90 Infected Devices Yielded in a Single Day

Each "piece" in the DAISY_CLOUD naming convention represents one infected device. From 90 machines, the operation extracted 1,174 credential records, averaging just over 13 credentials per device. That's a typical yield for browser-based infostealer malware, which pulls saved passwords and session data from whatever browsers are installed on the victim's computer.

The exposed data per record:

  • Email Addresses: 1,174 U.S. accounts
  • Plaintext Passwords: Captured in cleartext directly from browser storage
  • Target URLs: Login pages tied to each specific credential set

Daily Releases Mean Victims Are Never Notified

One of the most damaging aspects of ongoing operations like DAISY_CLOUD is that the pace of releases far outstrips any notification process. There's no organization on the other end to detect the breach and alert users. The credentials are stolen at the device level, aggregated, and posted to Telegram before any security system has flagged anything unusual. Victims recieve no warning.

By the time someone discovers their email in a DAISY_CLOUD batch, the password has often been in circulation for days or weeks. In that window, the accounts tied to that email may have been tested against dozens of services by automated credential stuffing tools. The financial and personal damage can already be done.


HEROIC Monitors DAISY_CLOUD's Ongoing Releases

The DarkHive team indexes each DAISY_CLOUD batch, including the February 25 release, into HEROIC's breach database, now covering more than 400 billion records. Their free scanner checks any email against the full dataset in seconds. If your credentials appeared in any DAISY_CLOUD release or similar Telegram stealer operation, you'll find out immediately.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 01 Apr 2026
Check in 5 seconds

1,174 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,056 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $8.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance