Inside iCloud Stealer Logs: 297,478 Passwords Harvested
HEROIC identified a stealer log file labeled "304K iCloud" distributed on Telegram in March 2023. This substantial dataset contains 297,478 records of compromised credentials specifically targeting iCloud and Apple ID users. Given that iCloud serves as the backbone of the Apple ecosystem, connecting devices, photos, messages, documents, and backups, the exposure of nearly 300,000 iCloud credentials represents one of the most consequential stealer log dumps in this category.
Plaintext Apple ID Passwords Unlock the Entire Ecosystem
All 297,478 passwords in this dataset are stored in plaintext. When the compromised password belongs to an Apple ID, the implications are vast. An Apple ID password does not just unlock iCloud email. It provides access to iCloud Drive documents, Photos library including personal and sensitive images, device backups that may contain messages and health data, Find My iPhone which reveals real-time device locations, and Apple Pay settings. A single plaintext iCloud credential is a master key to a victim's entire digital life on Apple platforms.
What Was Exposed
- Email Addresses — Apple ID accounts that serve as the gateway to all Apple services and connected devices
- Plaintext Passwords — unprotected credentials that provide immediate access to the Apple ecosystem
- URLs — the Apple and third-party login pages where each credential was intercepted by malware
Why iCloud Credential Stuffing Is Especially Dangerous
Attackers prize iCloud credentials above most other account types because of the depth of data they expose. With 297,478 working email-password pairs, credential stuffing campaigns against Apple services can unlock not just cloud storage but physical device control through Find My iPhone. Attackers can remotely lock devices and demand ransom, access iMessage history and contacts, download entire phone backups containing years of personal data, and use the compromised Apple ID to authenticate on third-party services that support Sign in with Apple.
The Technical Pipeline: From Malware to iCloud Credentials
These 297,478 credentials were harvested by infostealer malware operating on compromised Windows and Android devices. When victims logged into iCloud.com or Apple services through a browser on these infected devices, the malware captured their credentials in real time. Additionally, the malware extracted Apple ID passwords saved in browser credential stores and keychain-synced passwords accessible through Chrome or Firefox. The stolen data was compiled into log files, filtered to isolate Apple and iCloud credentials, and released as a targeted 304K-record dataset on Telegram for credential stuffing operators.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database contains over 400 billion records from data breaches, stealer logs, and dark web sources. Apple users should use the HEROIC breach scanner immediately to check whether their Apple ID email or password appears in the 304K iCloud dump. If your credentials are found, change your Apple ID password immediately, review all devices connected to your account, enable two-factor authentication, and check for any unauthorized access to your photos, files, and backups.
Breach Breakdown
297,478 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds