Breach Intelligence Report 11 Apr 2026

Dark Web Intel: 2,319 Credentials From the IQ-IRAQ-161PCS HEAVENLOGSCLOUD Dump

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs IQ-IRAQ-161PCS HEAVENLOGSCLOUD uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,319
Source Type Stealer log
Origin United States
Password Type plaintext

Dark web intelligence analysts tracking Telegram-based threat actor activity identified the IQ-IRAQ-161PCS HEAVENLOGSCLOUD stealer log in April 2023. The dataset, freely distributed on underground channels, contains 2,319 records harvested from Iraqi endpoints by information-stealing malware. Each record in the log represents a compromised device, complete with the email addresses, plaintext passwords, and browsing URLs that the malware silently extracted before transmitting the data to the threat actor's infrastructure. The log was subsequently shared across multiple dark web forums and Telegram groups.


Why This Is Dangerous

Stealer log data circulating on dark web forums and Telegram channels is classified as immediately actionable threat intelligence. Unlike a traditional database breach where passwords may be hashed and require cracking, stealer logs deliver credentials in plaintext form, ready to use with no additional effort. The 2,319 records in this dataset give attackers a verified list of active Iraqi internet users with known email and password combinations. Combined with URL metadata that reveals each victim's active online accounts, this data enables targeted account takeover with a high probability of success against the most valuable services each victim uses.


What Was Exposed

  • Email Addresses
  • Plaintext Passwords
  • URLs (sites and services accessed on infected devices)

Why This Matters

Dark web intelligence on Iraqi endpoints is a growing category of threat data as internet adoption in the region continues to expand. Criminals who aquire this log gain access to credentials spanning personal email accounts, social media profiles, and potentially business systems. Many users in the region have not adopted multi-factor authentication, making credential stuffing attacks particularly effective. Email adresses from this dataset can also be used for targeted phishing campaigns, allowing attackers to craft convincing messages that appear to come from services the victim is known to use. The downstream risk extends to family members and colleagues who may recieve fraudulent messages from a compromised account.


How Stealer Logs Work

The HEAVENLOGSCLOUD stealer log format is associated with commodity information-stealing malware that has been widely distributed on dark web markets and Telegram channels. These stealers infect devices through phishing links, trojanized software installers, and malicious email attachments. After infection, the malware harvests credentials from all major browsers, reads saved WiFi passwords, extracts cryptocurrency wallet files, and captures screenshots. The collected data is compressed and uploaded to a cloud storage service or dedicated command-and-control server before being distributed. Each bundle of logs, or package of compromised machine data, is labeled by country code and endpoint count, which is reflected in the source name of this breach. The exfiltration process is fully automated and typically completes before the user notices any change in device performance.


Check If You Are Affected

If you or your organization operates in Iraq or the surrounding region, your credentials may be part of this dataset. HEROIC's free breach scanner cross-references your email address against more than 400 billion compromised records sourced from dark web forums, Telegram channels, and stealer log dumps exactly like this one. Check your exposure for free at HEROIC now. Dark web actors already have this data -- find out if your email is in it before they use it against you.

Breach Breakdown

Domain IQ-IRAQ-161PCS HEAVENLOGSCLOUD uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 11 Apr 2026
Check in 5 seconds

2,319 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,227 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $16.8K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance