DaisyCloud-Championing Telegram Leak: 18,659 U.S. Credentials (Apr 20, 2024)
April 20: The Consecutive Run Deepens Into Mid-April
The release of 18,659 U.S. infostealer credentials on April 20, 2024 by NEW_DAISYCLOUD-CHAMPIONING is another datapoint in an expaning documented series. The confirmed floor of this campaign has now moved back to at least April 18, with April 20 confirming uninterrupted output through the middle of the month. With evry newly confirmed date, the picture of this campaign becomes clearer -- and larger.
NEW_DAISYCLOUD-CHAMPIONING April 20, 2024: Breach Summary
- Records Exposed: 18,659
- Data Types: Email addresses, plaintext passwords, target login URLs
- Breach Type: Infostealer malware log
- Country Affected: United States
- Date Leaked: April 20, 2024
Mid-April Credentials: Still at Scale
The 18,659 records released on April 20 are in the lower-to-middle range of the documented series -- but they are by no means insignificant. 18,659 U.S. credential sets, each containing an email address, a plaintext password, and a target login URL, represents a substancial daily release by any measure. The channel was presistently producing thousands of records per day, week after week. The April 20 release confirms that this volume was being sustained not just through May, but also through the heart of April. The operation had a scale and momentum that did not depend on any single high-volume day.
The Compounding Risk of Multi-Week Credential Exposure
When credentials are exposed over a 33+ day consecutive period -- as the NEW_DAISYCLOUD-CHAMPIONING series now documents -- the risk to affected individuals compounds. Each day's release makes the total dataset larger, increasing the likelhood that any given user's credentials appear somewhere in the series. More critically, the extended distribution window means that the data had been accessible to attackers for weeks before most affected individuals would have had any chance to respond. Credentials relased in mid-April were potentially being used for account takeover attempts while the campaign was still actively releasing new batches in May. The April 20 entry is a reminder that the damage from a sustained campaign accumulates -- it doesn't reset with each new release.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records, including infostealer logs from Telegram campaigns like NEW_DAISYCLOUD-CHAMPIONING. Check whether your email was exposed -- and if it was, change your passwords immediately.
Breach Breakdown
18,659 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds