If You Reuse Passwords, the DVDCLOUDFree 16K Leak Matters
In February 2024, HEROIC detected yet another stealer log release from DVDCLOUDFree on Telegram, this one containing 16,071 compromised records. This is among the larger releases from this prolific threat actor, with each record containing an email address, a plaintext password, and the URL of the service where the credential was intercepted. The scale of this release increases the statistical probability that any given internet user's credentials are included.
Plaintext Passwords Remove Every Layer of Defense
The 16,071 passwords in this dataset are fully readable, stored without any encryption, hashing, or obfuscation. When a website properly stores your password, it transforms it into a hash that is extremely difficult to reverse. But credentials stolen by infostealer malware bypass this protection entirely because they are captured before the website receives them. The result is a file full of passwords exactly as you typed them, ready for anyone to use.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of compromised websites and services
Why This Leak Matters Most to Password Reusers
If you use the same password on more than one website, you are the primary target of datasets like this. Attackers do not manually test 16,071 credentials one by one. They load the entire list into automated tools that attempt each email and password combination against dozens of services in parallel. If your email and a reused password appear in this dataset, every account that shares that password is at risk, including accounts on services that were never directly breached.
DVDCLOUDFree's Persistent Threat to U.S. Users
DVDCLOUDFree has released multiple stealer log batches on Telegram, collectively exposing tens of thousands of credentials from U.S.-based internet users. The threat actor's infostealer malware infiltrates devices through a variety of attack vectors, including fraudulent email attachments, compromised software distribution sites, and malicious browser extensions. Each infected machine contributes its stored credentials to the growing pool of data that DVDCLOUDFree distributes. This 16,071-record batch is just one piece of a much larger operation.
Check If Your Credentials Were Exposed
HEROIC has compiled over 400 billion compromised records into a searchable breach intelligence database. Check whether your email or password was captured in this DVDCLOUDFree release by running a search in the HEROIC breach scanner. If you discover your credentials in this dataset, change your password on every account where you used it, prioritizing email, banking, and any service that holds sensitive personal information.
Breach Breakdown
16,071 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds