DAISY_CLOUD February 25: 90 Infected Devices, 1,174 U.S. Credentials Stolen
DAISY_CLOUD February 25: Another Day, Another Batch of Stolen Credentials
DAISY_CLOUD releases stealer logs in daily batches, each labeled with a date and a piece count. The February 25 release, labeled "90 PCS," came from 90 compromised devices and contained 1,174 U.S. credential records. The following day's batch had 103 devices. The pattern is systematic: infostealer malware runs continuously across a fleet of infected machines, and the operator uploads fresh batches to Telegram on a near-daily schedule.
HEROIC's DarkHive team confirmed the February 25 dataset: email addresses, plaintext passwords, and target login URLs, all from U.S. accounts, all from real people who had no idea their credentials were being packaged up and sent to Telegram.
What 90 Infected Devices Yielded in a Single Day
Each "piece" in the DAISY_CLOUD naming convention represents one infected device. From 90 machines, the operation extracted 1,174 credential records, averaging just over 13 credentials per device. That's a typical yield for browser-based infostealer malware, which pulls saved passwords and session data from whatever browsers are installed on the victim's computer.
The exposed data per record:
- Email Addresses: 1,174 U.S. accounts
- Plaintext Passwords: Captured in cleartext directly from browser storage
- Target URLs: Login pages tied to each specific credential set
Daily Releases Mean Victims Are Never Notified
One of the most damaging aspects of ongoing operations like DAISY_CLOUD is that the pace of releases far outstrips any notification process. There's no organization on the other end to detect the breach and alert users. The credentials are stolen at the device level, aggregated, and posted to Telegram before any security system has flagged anything unusual. Victims recieve no warning.
By the time someone discovers their email in a DAISY_CLOUD batch, the password has often been in circulation for days or weeks. In that window, the accounts tied to that email may have been tested against dozens of services by automated credential stuffing tools. The financial and personal damage can already be done.
HEROIC Monitors DAISY_CLOUD's Ongoing Releases
The DarkHive team indexes each DAISY_CLOUD batch, including the February 25 release, into HEROIC's breach database, now covering more than 400 billion records. Their free scanner checks any email against the full dataset in seconds. If your credentials appeared in any DAISY_CLOUD release or similar Telegram stealer operation, you'll find out immediately.
Breach Breakdown
1,174 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds