Breach Intelligence Report 14 Jul 2026

Inside iCloud Stealer Logs: 297,478 Passwords Harvested

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs 304k ICLOUD uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 297,478
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC identified a stealer log file labeled "304K iCloud" distributed on Telegram in March 2023. This substantial dataset contains 297,478 records of compromised credentials specifically targeting iCloud and Apple ID users. Given that iCloud serves as the backbone of the Apple ecosystem, connecting devices, photos, messages, documents, and backups, the exposure of nearly 300,000 iCloud credentials represents one of the most consequential stealer log dumps in this category.


Plaintext Apple ID Passwords Unlock the Entire Ecosystem

All 297,478 passwords in this dataset are stored in plaintext. When the compromised password belongs to an Apple ID, the implications are vast. An Apple ID password does not just unlock iCloud email. It provides access to iCloud Drive documents, Photos library including personal and sensitive images, device backups that may contain messages and health data, Find My iPhone which reveals real-time device locations, and Apple Pay settings. A single plaintext iCloud credential is a master key to a victim's entire digital life on Apple platforms.


What Was Exposed

  • Email Addresses — Apple ID accounts that serve as the gateway to all Apple services and connected devices
  • Plaintext Passwords — unprotected credentials that provide immediate access to the Apple ecosystem
  • URLs — the Apple and third-party login pages where each credential was intercepted by malware

Why iCloud Credential Stuffing Is Especially Dangerous

Attackers prize iCloud credentials above most other account types because of the depth of data they expose. With 297,478 working email-password pairs, credential stuffing campaigns against Apple services can unlock not just cloud storage but physical device control through Find My iPhone. Attackers can remotely lock devices and demand ransom, access iMessage history and contacts, download entire phone backups containing years of personal data, and use the compromised Apple ID to authenticate on third-party services that support Sign in with Apple.


The Technical Pipeline: From Malware to iCloud Credentials

These 297,478 credentials were harvested by infostealer malware operating on compromised Windows and Android devices. When victims logged into iCloud.com or Apple services through a browser on these infected devices, the malware captured their credentials in real time. Additionally, the malware extracted Apple ID passwords saved in browser credential stores and keychain-synced passwords accessible through Chrome or Firefox. The stolen data was compiled into log files, filtered to isolate Apple and iCloud credentials, and released as a targeted 304K-record dataset on Telegram for credential stuffing operators.


Check If Your Credentials Were Exposed

HEROIC's breach intelligence database contains over 400 billion records from data breaches, stealer logs, and dark web sources. Apple users should use the HEROIC breach scanner immediately to check whether their Apple ID email or password appears in the 304K iCloud dump. If your credentials are found, change your Apple ID password immediately, review all devices connected to your account, enable two-factor authentication, and check for any unauthorized access to your photos, files, and backups.

Breach Breakdown

Domain 304k ICLOUD uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

297,478 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,261 scanned today
Breach Rank #N/A by affected users
Impact Score
12
sensitivity + scale + recency
Est. Financial Impact $2.2M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance