Breach Intelligence Report 19 Sep 2025

GODELESS CLOUD Stealer Log: 6,986 US Records From a September 2023 Telegram Upload

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 6,986
Source Type Stealer log
Origin Telegram
Password Type plaintext

GODELESS CLOUD: 6,986 US Credentials in the September 29, 2023 Stealer Log Cluster

The GODELESS CLOUD stealer log dataset is the smallest of four uploads released on September 29, 2023 -- a single Telegram upload event that also included STARLINKCLOUD (75,634 records), STARLINKCLOUD2 (61,216 records), and a date-named log with 20,795 records. At 6,986 US credentials, the GODELESS CLOUD dataset is miniscule by comparison, but its inclusion in the September 29 cluster is notable. Small datasets released alongside large ones represent a distinct infection cluster with a separate victim population. The GODELESS CLOUD name, like its STARLINKCLOUD siblings, is likely deliberate obfuscaton designed to make the dataset appear more targeted or interesting to buyers, while the actual data follows the standard stealer log structure: plaintext passwords, endpoint URLs, and API host data from infected US devices.


GODELESS CLOUD (September 2023): Breach Summary

  • Records Exposed: 6,986
  • Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
  • Breach Type: Stealer log
  • Password Type: Plaintext -- directly usable with no cracking required
  • Country: United States
  • Date Leaked: September 29, 2023

Small Dataset, Full Exposure: Why 6,986 Records Still Matters

In the context of a 164,000-record upload cluster, 6,986 records might seem marginal. But for each of the individuals whose credentials appear in the GODELESS CLOUD dataset, the size of the broader cluster is irrelevant. Each of the 6,986 records represents a specific person's email address, plaintext password, and the exact URL where that credential authenticates. There's no cracking step, no credential enrichment required. An attacker with this dataset can begin testing each credential against its mapped endpoint URL immediately upon acquisition. Financial institutions, employer portals, healthcare providers, and subscription services appearing in the endpoint URL data face direct, targeted account takeover risk from every record in this batch.


Cloud-Themed Naming: Threat Actor Branding and Misdirection

The GODELESS CLOUD name is almost certainly assigned by the distributor rather than reflecting the actual breach source. Cloud-themed names like GODELESS CLOUD and STARLINKCLOUD serve two functions in the stealer log marketplace: they suggest the data contains cloud service credentials (increasing perceived value), and they create a legitmate-sounding label that can be referenced across multiple transactions. Security researchers tracking stealer log distributions often use these names as attribution markers to link multiple uploads to the same threat actor, even when the actual data sources differ. The GODELESS CLOUD name's co-release with STARLINKCLOUD and STARLINKCLOUD2 on September 29 suggests they originate from the same distribution network.


September 29, 2023: The Multi-Upload Context

The GODELESS CLOUD dataset's September 29, 2023 upload date places it within a coordinated four-dataset release event that collectively delivered over 164,000 US stealer log records to threat actor networks in a single day. This same multi-upload pattern -- multiple datasets, same channel, same day -- appeared in later campaigns like AuroraLogsTeam's five-batch April 5, 2025 release. The September 29, 2023 cluster may represent an earlier iteration of the same operational approach, suggesting this coordinated release methodology has been a persistent tactic in the stealer log distribution ecosystem for at least 18 months across multiple threat actor groups.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records including stealer log data from the September 2023 GODELESS CLOUD upload cluster. If your credentials were among the 6,986 records in this dataset, they have been in active circulation since September 2023. Check your exposure for free at HEROIC.com now.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 19 Sep 2025
Check in 5 seconds

6,986 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,532 scanned today
Breach Rank #16,529 by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $50.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance