US Users Targeted in 1,252-Record NEXUCLOUD Stealer Breach
HEROIC found the NEXUCLOUD stealer log on 21-Dec-2025, a file exposing 1,252 records containing email addresses, plaintext passwords, and the URLs of services where those credentials were harvested from compromised devices. The log targeted US users and was distributed through a Telegram channel.
Why the NEXUCLOUD Breach Is Dangerous
With US users specifically in the crosshairs, this breach enables targeted credential stuffing against US-based banking, e-commerce, and email services. The plaintext passwords make every stolen record immediately actionable for account takeover without any additional processing.
What Was Exposed in the NEXUCLOUD Leak
- Email addresses
- Plaintext passwords
- URLs (the exact services where credentials were captured from infected devices)
Why This NEXUCLOUD Data Puts You at Risk
Credential stuffing, account takeover, identity theft, and financial fraud are all immediate risks when email-password pairs are exposed in plaintext. Attackers automate login attempts across hundreds of platforms, and victims typically have no warning until accounts are compromised.
How Stealer Log Works
Infostealer malware spreads through phishing campaigns, trojanized software, and malicious downloads. After infecting a device, it harvests stored credentials from browsers and apps, then sends the data to attacker-controlled infrastructure. The resulting logs are packaged and distributed through Telegram channels and dark web forums.
Check If Your Data Was Exposed
HEROIC operates one of the world's largest breach databases, covering more than 400 billion leaked records. Use HEROIC's free breach scanner to check if your email address or credentials appeared in the NEXUCLOUD leak or thousands of other breaches in our database.
Breach Breakdown
1,252 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds