Nullcyber Cloud Stealer Log: Someone Could Be In Your Accounts
HEROIC analysts uncovered a stealer log file named ULP_Private_475659_150426_Nullcyber_Cloud, uploaded by a Telegram user and dated April 16, 2026. The log contains 128,070 records, each one an email address paired with a plaintext password and the exact URL that combination logs into. The "Private" label in the file name suggests it was meant to circulate in smaller, invite-only groups before spreading more widely, which is exactly what appears to have happened.
Why the Nullcyber Cloud Stealer Log Is Dangerous
This is the kind of leak where someone else could already be signing into your accounts without you knowing it. Because every record pairs a real password with the exact site it belongs to, there is nothing standing between the data and an attacker's next login attempt. With 128,070 entries in the file, criminals have a large, ready-to-use list of working credentials they can test immediately, no cracking tools or guesswork required.
What Was Exposed in the Nullcyber Cloud Leak
- Email addresses connected to real user accounts
- Plaintext passwords stored without any encryption
- URLs identifying exactly which site or service each login unlocks
Why This Matters for the 128,070 People in This Leak
If your credentials are part of this dump, someone could be logging into your email, streaming services, or online banking right now without your knowledge. Attackers commonly automate this process, running the leaked email and password pairs through credential stuffing scripts that check dozens of popular sites in seconds. If a password was reused anywhere else, that account becomes a target too. This is how a single stealer log spirals into identity theft, unauthorized charges, and locked accounts that take days to recover.
How a "Private" Stealer Log Like This Gets Made and Leaked
Stealer malware infects a device through phishing emails, cracked downloads, or malicious ads, then quietly copies saved browser credentials and packages them into a ULP file, short for URL, login, and password. Files labeled "private" are usually shared first within a closed group or sold to a small number of buyers, giving the operator, in this case tied to the name Nullcyber Cloud, time to profit before the data eventually leaks more broadly on Telegram. Once that happens, as it has here, the file becomes accesible to anyone who wants it.
Check If You Are Affected by the Nullcyber Cloud Leak
You don't have to wonder whether someone is using your login without permission. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this Nullcyber Cloud stealer log, so you can confirm your exposure in seconds. If you find a match, change that password immediately and turn on two-factor authentication wherever it's available. Scan now to lock attackers out before they get any further in.
Breach Breakdown
128,070 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds