Breach Intelligence Report 24 Apr 2026

The I COUNTRY DIAMOND_logscloud Dump: 2,845 Stolen Login Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs I COUNTRY - 258PCS DIAMOND_logscloud uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,845
Source Type Stealer log
Origin United States
Password Type plaintext

In June 2023, a stealer log file containing 2,845 stolen login credentials was dumped on Telegram by an anonymous threat actor operating under the I COUNTRY DIAMOND_logscloud collection label. The breech exposed email addresses, plaintext passwords, API host information, and URLs harvested directly from infected endpoints by credential-stealing malware running silently in the background. Victims likely recieved no notification that their login credentials had been captured and distributed through criminal channels. HEROIC analysts have confirmed this dataset circulating among criminal networks and verified the records are authentic and actionable by attackers.


Why This Is Dangerous

Plaintext passwords paired with email addresses give criminals everything they need to attempt immediate account takeovers across dozens of platforms with no additional preparation. Attackers know that most users reuse the same password on multiple services, meaning a single stolen credential can compromise banking, email, and social media accounts simultaniously. The URL data in this dump makes attacks even more precise, as criminals already know which specific platforms each victim uses rather than having to test broadly. Every month these credentials remain unaddressed increases the window of risk for the 2,845 affected victims.


What Was Exposed

  • Email Addresses: Primary identifiers used to target victims across multiple platforms and initiate phishing campaigns, also serving as the recovery address criminals can exploit to reset passwords on linked accounts.
  • Plaintext Passwords: Unencrypted login credentials captured directly from infected devices at the moment of use, ready for criminals to deploy immediately without any cracking or decryption required.
  • URLs: The specific websites and services victims were logged into when malware captured their credentials, revealing exactly which accounts are at highest risk from this dataset.

Why This Matters

The 2,845 records from this I COUNTRY DIAMOND_logscloud dump are precisely the type of data that powers credential stuffing campaigns, where automated tools test stolen email and password pairs against hundreds of websites simultaneously. Because most people reuse passwords, attackers can achieve significant success rates even with datasets that are months or years old. Victims whose information appears in this dump may find their accounts accessed long after the initial theft, having forgotten the original breach ever occured. Credentials from dumps like this one are also traded and re-sold on dark web marketplaces, meaning exposure compounds over time as more criminals gain access.


How Stealer Log Breaches Work

A stealer log breach occurs when malware secretly installed on a victim's device harvests saved passwords, browser session cookies, and login URLs in real time. Unlike traditional database breaches, stealer logs capture credentials exactly as the victim types or auto-fills them, bypassing encryption entirely. The malware often spreads through pirated software, malicious email attachments, or compromised download sites, meaning victims rarely know they are infeccted. Once collected, these logs are packaged and sold or shared on Telegram channels and dark web forums by threat actors like the one behind the I COUNTRY DIAMOND_logscloud dump.


Check If You Are Affected

HEROIC's free dark web scanner searches across more than 400 billion exposed records to tell you instantly whether your email address or passwords appear in known breach datasets, including stealer log collections like the I COUNTRY DIAMOND_logscloud dump. Visit heroic.com to run your free scan now and find out if your credentials have been compromised. Early detection is the single most effective step you can take to protect your accounts before criminals act on the stolen data already in their hands.

Breach Breakdown

Domain I COUNTRY - 258PCS DIAMOND_logscloud uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 24 Apr 2026
Check in 5 seconds

2,845 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,532 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $20.6K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance