The Everlasting_Cloud Leak Could Unlock Your Email and Bank Accounts
We noticed a recent upload to a public Telegram channel on April 18, 2025, containing a stealer log file. This log appears to originate from compromised endpoints, detailing user credentials and associated URLs. What struck us was the direct exposure of plaintext passwords, a critical vulnerability that significantly elevates the risk of further compromise for affected users and potentially the organization if these credentials are reused.
The uploaded stealer log, attributed to a Telegram user, contains 3894 records. Each record details an endpoint, an associated email address, an API host, and crucially, a plaintext password. The data structure suggests these logs were exfiltrated from infected machines, likely via infostealer malware. The presence of URLs alongside credentials could indicate compromised browser sessions or direct access to web-based services. The direct exposure of such sensitive information, particularly in plaintext, bypasses many standard security controls and presents an immediate threat of account takeover and lateral movement within connected systems.
While no direct news coverage has emerged regarding this specific data dump, the proliferation of stealer logs on platforms like Telegram is a well-documented phenomenon. Security researchers frequently highlight the ongoing threat posed by infostealer malware, which is often distributed through phishing campaigns or malicious downloads. The ease with which these logs can be shared and accessed on public forums amplifies the impact of such breaches, enabling opportunistic attackers to quickly harvest credentials for widespread exploitation.
Breach Breakdown
3,894 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds