How Malware Led to 297,297 Stolen Cloud Logins
HEROIC uncovered a large multinational combolist labeled "Canada Vietnam Cloud Private" on Telegram in April 2025. The file contains 297,297 records targeting cloud service accounts across both Canada and Vietnam, with each entry providing an email address, a plaintext password, and the URL of the cloud platform where the credential was intercepted. The cross-border scope and cloud focus of this dump make it a significant threat to both individual users and organizations.
Nearly 300,000 Cloud Passwords Exposed in Plaintext
Every password in this 297,297-record collection is stored in plaintext without any cryptographic protection. Cloud service credentials are among the highest-value targets for cybercriminals because they can provide access to stored files, business data, virtual machines, email, and collaboration tools. With plaintext passwords, attackers can attempt logins immediately, targeting cloud dashboards that may contain sensitive personal or corporate information.
What Was Exposed
- Email Addresses — from Canadian and Vietnamese cloud service users
- Plaintext Passwords — entirely unencrypted and ready for immediate exploitation
- URLs — identifying specific cloud platforms and services targeted across both countries
Cross-Border Credential Stuffing Multiplies the Threat
A combolist spanning two countries gives attackers access to a diverse set of cloud ecosystems. Canadian users may have credentials linked to government services, banking platforms, and enterprise cloud deployments, while Vietnamese users face risks to local e-commerce, communication, and cloud storage services. Credential stuffing tools can simultaneously test these 297,297 pairs against AWS, Azure, Google Cloud, and regional cloud providers, exploiting password reuse across all of them.
The Malware Campaign Behind the Combolist
The dual-country focus of this dump suggests a coordinated infostealer campaign targeting users in both Canada and Vietnam. The malware may have spread through localized phishing campaigns, compromised software in both English and Vietnamese, or through popular cloud tool installers. Once active on a device, the stealer captures cloud portal credentials alongside every other login, then transmits the data to operators who sort, filter, and distribute it by geography and service type on Telegram.
Check If Your Credentials Were Exposed
Users of cloud services in Canada and Vietnam, as well as anyone who accesses cloud platforms internationally, should check their exposure. HEROIC's breach scanner indexes over 400 billion compromised records and can determine whether your email or password has been leaked in this combolist or any other known breach. Search your credentials now and immediately update any cloud service passwords that may be compromised, enabling multi-factor authentication wherever available.
Breach Breakdown
297,297 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds