DaisyCloud-Championing Jun 7 2024: 5,894 U.S. Credentials in Staggered June Release Cluster
HEROIC's DarkHive intelligence system detected the NEW_DAISYCLOUD-CHAMPIONING June 7, 2024 release, exposing 5,894 U.S. credential records on Telegram. This drop falls in the middle of a documented cluster of releases from this channel spanning June 6, 7, and 12, 2024 -- a staggered release pattern characteristic of organized infostealer distribution operations. The data includes email addresses, plaintext passwords, and login URLs harvested from infected U.S. devices, consistent with standard infostealer log format. This release predates the 2025 Slurm Logs and PegasusCloud campaigns by over a year, demonstrating that Telegram-based infostealer networks were well-established in mid-2024.
Why This Is Dangerous
Credentials in this release have been accessible to threat actors for over a year since the June 2024 leak date. Plaintext passwords require no cracking -- anyone recieving this data can attempt logins on the spot. Thier inclusion of login URLs alongside email and password transforms each record into a targeted access package, pointing attackers directly to the services where each credential was used. Victims who have not changed passwords since June 2024 remain at risk on every platform where they reused the same credential.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Login URLs
Why This Matters
Infostealer logs from 2024 continue to circulate in secondary credential markets throughout 2025. Threat actors test and retell these datasets against current services, exploiting victims who have not yet changed their passwords. Victims who reuse passwords across seperate platforms face ongoing risk on every service that shares the compromised credential. Anyone who used a device infected by infostealer malware in early 2024 should immediatly audit all active accounts for signs of unauthorized access and update passwords associated with any potentially affected email address.
How Stealer Logs Work
Stealer logs are produced by infostealer malware distributed through phishing emails, cracked software, and malicious browser extensions. Once installed on a victim's device, the malware silently captures credentials from browsers and applications, then sends them to attacker-controlled servers. NEW_DAISYCLOUD-CHAMPIONING operators compiled harvested records and released them in a staggered cadence across multiple days in June 2024 -- maximizing channel engagement and allowing individual batches to be sold or distributed separately. The June 7 drop is the second in the documented cluster, following a June 6 release and preceding a June 12 release.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from breaches like NEW_DAISYCLOUD-CHAMPIONING. Visit heroic.com to scan your email address and find out if your information was exposed in this June 2024 stealer log release.
Breach Breakdown
5,894 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds