Breach Intelligence Report 28 Apr 2026

24K Records Gone: MetaCloudVipNew Stealer Log Hits Telegram

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs MetaCloudVipNew 400 PCs uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 24,121
Source Type Stealer log
Origin United States
Password Type plaintext

In December 2025, a Telegram user released a stealer log file under the MetaCloudVipNew 400 PCs label, distributing 24,121 harvested records to anyone who wanted them. The data includes email addresses, plaintext passwords, and URLs, the complete set of information needed to walk directly into the online accounts of every person whose credentials appear in this file.

The "400 PCs" label in the file name refers to the approximate number of infected machines this batch was harvested from. That means on average, each device contributed roughly 60 stolen records to this file. For victims, that volume of data per device suggests deep, sustained infection rather than a quick credential grab.


Inside the MetaCloudVipNew Breach: Stolen Data Summary

  • Records exposed: 24,121
  • Date leaked: December 1, 2025
  • Breach type: Stealer log (malware-harvested credentials)
  • Data compromised: Email addresses, plaintext passwords, URLs
  • Country of origin: United States
  • Distribution method: Telegram upload
  • Password format: Plaintext, readable without any decryption
  • Estimated source machines: Approximately 400 infected devices

What Victims of MetaCloudVipNew Face: Real Security Risks

Twenty-four thousand records from 400 infected machines is not a small targeted operation. This is bulk credential harvesting at scale, and the risks for each victim are immediate:

  • Credential stuffing: Every email and plaintext password in this file gets tested against banking platforms, email providers, social media, and subscription services automatically. One password reused anywhere translates directly into a compromised account.
  • Account takeover: Attackers who gain email access change recovery settings and lock victims out. Many people loose access permanantly because they don't realise what happened until the recovery window has closed.
  • Identity misuse: Email access allows criminals to impersonate you to your contacts, intercept financial communications, and request password resets on linked services without triggering any alerts.
  • Ongoing resale: MetaCloudVipNew logs get distributed through Telegram and then traded further on dark web markets. Your credentials may be actively used by multiple threat actors simultaneously.

The Stealer Log Pipeline: From Infection to Dark Web Sale

The "400 PCs" naming convention tells us exactly how this operation works at the ground level. Here is the full picture:

  • Device targeting and infection: Infostealer malware is distributed through malicious ads, pirated software, fake game cheats, and phishing links. The attacker's goal is volume, infecting as many machines as possible in a single campaign.
  • Silent harvesting: Once installed, the malware captures every saved password in the browser, active session tokens, and URLs of recently visited sites. On a typical device this takes under a minute to complete.
  • Batch assembly: The attacker aggregates logs from all infected machines into named batches, often indicating the machine count in the file name to signal batch quality to buyers.
  • Telegram listing: The assembled file is uploaded to a Telegram channel like MetaCloudVipNew, reaching an audience of credential buyers, identity thieves, and fraudsters simultaneously.
  • Multi-stage exploitation: Buyers run credential stuffing campaigns, perform targeted account takeovers, and resell particularly valuable logins to specialized criminals.

Check Your MetaCloudVipNew Breach Exposure for Free

HEROIC's breach search database indexes over 400 billion exposed records, including stealer log batches distributed through Telegram channels like MetaCloudVipNew. If your email appeared in this file, you can find out instantly for free. Search now, immediately rotate any exposed passwords, and activate two-factor authentication on every account linked to that email address.

Breach Breakdown

Domain MetaCloudVipNew 400 PCs uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 28 Apr 2026
Check in 5 seconds

24,121 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,257 scanned today
Breach Rank #N/A by affected users
Impact Score
1
sensitivity + scale + recency
Est. Financial Impact $174.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance