Dark Web Alert: 818,249 Records from Cloud T98 Leaked
HEROIC has flagged a massive stealer log collection identified as Cloud T98 that surfaced on dark web platforms in July 2026. With 818,249 compromised records, this is one of the larger credential dumps recently identified by HEROIC's threat intelligence operations, indicating a widespread infostealer malware campaign affecting users across numerous online services.
Over 800,000 Plaintext Passwords Now Circulating
The Cloud T98 breach contains more than 800,000 passwords stored in plaintext, a staggering volume of instantly exploitable credentials. At this scale, the data set almost certainly includes passwords for banking portals, enterprise systems, healthcare platforms, and critical infrastructure services. Each plaintext password requires zero processing to use, giving attackers the ability to begin mass account compromise operations immediately upon obtaining the data.
What Was Exposed
- Email Addresses — over 818,000 unique email accounts identified as login credentials
- Plaintext Passwords — a vast collection of unencrypted, immediately usable passwords
- URLs — hundreds of thousands of login pages and web services mapped to stolen credentials
Credential Stuffing at Unprecedented Scale
An 818,249-record data set provides cybercriminal organizations with the raw materials for massive credential stuffing campaigns that can run for weeks or months. These operations systematically test every email-password pair against the login pages of major banks, cryptocurrency exchanges, email providers, and social media platforms. With this volume of credentials and the prevalence of password reuse among internet users, attackers can expect to compromise tens of thousands of additional accounts across unrelated services.
Infostealer Malware Operations at Scale
The sheer size of the Cloud T98 collection points to a well-resourced infostealer malware operation capable of infecting hundreds of thousands of devices. These operations leverage multiple distribution channels simultaneously, including malspam campaigns, SEO-poisoned search results, fake software crack sites, and compromised advertising networks. The malware harvests every saved credential, cookie, and session token on each infected device, aggregating everything into massive log collections that are then sold on dark web marketplaces for substantial sums.
Check If Your Credentials Were Exposed
With over 400 billion records in its breach intelligence database, HEROIC offers the most thorough credential monitoring available anywhere. Run a free scan with HEROIC's breach checker to determine if your email or password appeared in the Cloud T98 data set or any of the other breaches and stealer logs that HEROIC continuously tracks.
Breach Breakdown
818,249 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds