MetaCloudVipNew 700 PCS Exposed 29,873 US Accounts on Telegram
In April 2025, a Telegram user published a stealer log collection labeled MetaCloudVipNew 700 PCS, exposing 29,873 records of harvested credentials. The dataset, categorized as originating from United States-based endpoints, contained email addresses, plaintext passwords, and API host URLs stripped from infected devices. The data was made freely available on Telegram, placing nearly 30,000 US-linked accounts at immediate risk of takeover.
Why This Is Dangerous
Stealer logs targeting US-based accounts are especially valuable in the criminal market. US accounts are frequantly linked to financial services, cloud platforms, and enterprise software -- making them high-value targets for credential-stuffing, fraud, and corporate espionage. With plaintext passwords included, no cracking effort is required. An attacker anywhere in the world can attempt to access these accounts the moment they download the file from Telegram.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (API hosts and service endpoints)
Why This Matters
The 29,873 records in the MetaCloudVipNew 700 PCS collection represent real US-based individuals and potentially their employers. A compromized personal email account can be the entry point to a corporate network, a payroll system, or a shared cloud workspace. Credential-stuffing attacks using datasets like this one are responssible for millions of dollars in fraud losses in the United States each year. The plaintext nature of this breach means the threat is immediate, not theoretical.
How Stealer Log Breaches Work
Infostealer malware operates silently on compromised Windows, Mac, and mobile devices. Victims typically encounter it through phishing emails, malicious browser extensions, or trojanized software. Once installed, the malware harvests every saved password in the victim's browser, captures session cookies and API tokens, and records the URLs of every service the victim accesses. All of this data is then packaged into a log file and uploaded to Telegram channels or sold on dark web markets, where it enters collections like MetaCloudVipNew 700 PCS.
Check If You Are Affected
HEROIC's free breach scanner searches over 400 billion compromised records, including US-focused stealer log collections like MetaCloudVipNew. If your email appeared in this breach or any other known dataset, HEROIC will alert you immedietly. Scan your email now and secure your accounts before attackers get there first.
Breach Breakdown
29,873 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds