FASTCLOUDD x10000: 332,994 Stolen Records Now on the Dark Web
HEROIC analysts traced a stealer log file that surfaced on a public Telegram channel on December 20, 2022. The file, posted under the name FASTCLOUDD x10000, contained 332,994 records pulled from compromised endpoints. Each record included an email address, a plaintext password, and the URL where that credential was actively used. The sheer volume of this dataset signals a large-scale infostealer operation, not an isolated attack.
Why This Is Dangerous
With over 332,000 plaintext credential pairs in a single file, this dataset is exactly the kind of resource that fuels automated attacks at scale. Attackers do not read through these files manually. They feed them into credential stuffing tools that can test hundreds of combinations per second across dozens of platforms. One match means account takeover. And because the file was posted publicly on Telegram, it has been copied, reshared, and likely folded into dark web marketplaces where it could still be actively traded years after the original post.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (login endpoints and API hosts associated with each credential)
Why This Matters
A breach of this size creates lasting damage. Even if you changed your password in 2022, your old email and password combo may still be circulating on underground forums and dark web data dumps. Attackers use these older datasets to attempt account takeovers, commit identidy theft, manufacture fraudulant transactions, and in corporate environments, to gain an initial foothold for deeper network intrusion. The FASTCLOUDD x10000 dataset is large enough that many security researchers would flag it as a significant threat to any organization whose employees appear in it.
How Dark Web Data Markets Work
When a stealer log like FASTCLOUDD x10000 gets posted to Telegram, it quickly migrates. Buyers on dark web forums purchase credential lists in bulk. Some use them directly for credential stuffing. Others break them up and resell them by industry, country, or service type. HEROIC monitors these dark web channels constantly, tracking where stolen data moves and indexing it so you can find out if your information has been traded. The path from a Telegram post to active exploitation can take less than 24 hours, which is why early detection is critical.
Check If You Are Affected
HEROIC has indexed over 400 billion breached records, including the FASTCLOUDD x10000 dataset and thousands of similar dark web dumps. Use our free breach scanner to find out if your email address is part of this leak or any other known breach. Do not wait for an attacker to find you first. Run a free dark web check at HEROIC's breach scanner.
Breach Breakdown
332,994 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds