The MetaCloudVipNew Breach Hit 2,900 PCs in 2026. The Data Just Went Public.
What HEROIC Analysts Discovered
In January 2026, HEROIC analysts identified a major stealer log archive on Telegram under the name MetaCloudVipNew 2900 PCs.part1. The file was uploaded by an anonymous threat actor and is notable for its origin: data extracted from approximately 2,900 compromised computers. The archive contains 52,264 records, each including an email address, a plaintext password, and the URL of a service the victim was authenticated to at the time of infection. At over 52,000 records from a defined set of 2,900 machines, this dataset reflects extensive, multi-account harvesting from each infected device.
Why This Is Dangerous
The scale and source of the MetaCloudVipNew 2900 PCs.part1 dataset make it exceptionally dangerous. With an average of nearly 18 credential records per infected machine, attackers have extensive visibility into each victim's digital life. Plaintext passwords mean immediate usability, no cracking required. The URL data gives a precise roadmap of which services to target for each victim. Attackers who obtained this archive can conduct highly targeted account takeover campaigns against email providers, banking platforms, corporate systems, and cloud storage services, all within minutes of acquiring the file.
What Was Exposed
The following data types were confirmed in the MetaCloudVipNew 2900 PCs.part1 breach:
- Email Addresses
- Plaintext Passwords
- URLs (services the victim was authenticated to at time of infection)
Why This Matters
A dataset of this size and specificity creates significant risk for everyone included. Credential stuffing attacks using these records can succeed across email services, financial institutions, and corporate portals simultaneously. A compromised email account becomes a skeleton key, enabling attackers to reset passwords on every linked service. Victims face risks of financial fraud, identity theft, account takeover, and in cases where work credentials were captured, exposure of employer systems and data. Anyone whose device was compromised in this campaign and who has not since changed their passwords remains fully vulnerable.
How Stealer Log Breaches Work
The MetaCloudVipNew data was collected from approximately 2,900 devices infected with info-stealer malware. Tools like Redline, Raccoon, and Vidar infect computers silently through phishing emails, fake software installers, or malicious browser add-ons. Once installed, the malware runs in the background and extracts all saved passwords from the browser, captures active session cookies, and records the URLs of recently visited or authenticated services. The data from each machine is packaged into a log and transmitted to the attacker's server. The logs are then compiled into archive files and distributed on Telegram, where criminals use them for account takeover, credential stuffing, and identity fraud.
Check If You Are Affected
HEROIC's free breach scanner checks your email against a database of over 400 billion compromised records, including stealer logs like MetaCloudVipNew 2900 PCs.part1. If your credentials were captured from one of the 2,900 infected machines in this campaign, you will know immediately and can take action to secure your accounts. Run your free scan now at HEROIC.com.
Breach Breakdown
52,264 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds