US Users Targeted in the 9,913-Record Everlasting_Cloud_2 Breach
HEROIC found a stealer log called Everlasting_Cloud_2 circulating on a public Telegram channel, dated March 26, 2025. The file contains 9,913 records taken from infected US devices, pairing email addresses with plaintext passwords and the web addresses those passwords unlock.
Why This Is Dangerous
With 9,913 plaintext credentials bundled into one file, this leak hands attackers a ready-made toolkit. There's no hash to break, only an email, a password, and the web address it belongs to.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to the affected accounts
Why This Matters
Attackers rely on leaks like this for credential stuffing, running stolen login pairs against banking portals, email providers, and shopping accounts. A single reused password can escalate quickly into account takeover, financial fraud, or identity theft.
How Stealer Logs Work
Stealer logs are built by malware that infects a device, often through a fake download or cracked software, then quietly exports saved passwords and their matching URLs. Files like this Everlasting_Cloud_2 log are commonly shared or sold on Telegram channels set up for trading stolen data.
Check If You Are Affected
HEROIC's free breach scanner searches over 400 billion leaked records to see if your email turns up in this leak or others. Run a scan now and change any reused passwords right away.
Breach Breakdown
9,913 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds