324,958 Records Leaked: Inside the Nullcyber Cloud ULP Breach
324,958. That is how many username-password-URL combinations showed up in a file tied to the source Nullcyber Cloud, posted by a Telegram user in November 2025. This kind of dump is often called a ULP, short for URL-Login-Password, and it is one of the most commonly traded formats on dark web marketplaces because it is imediately usable the moment someone downloads it.
Why This Is Dangerous
Unlike a database dump from a single company, a ULP file like this one pulls together logins from dozens or hundreds of different websites into one neat package. That means the 324,958 records here are not tied to one service, they represent whatever sites the victims happened to be logged into when their devices got compromised. Because the passwords were stored in plaintext, there is no encryption standing between an attacker and full account access.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs for the associated accounts
- 324,958 total records
Why This Matters
Files like this get passed around, resold, and merged into bigger combolists almost as soon as they surface. Once that happens it becomes nearly imposible to track wich services were actually hit and wich accounts are still exposed. Anyone whose email shows up in a leak like this should treat every password tied to that address as compromised.
How ULP Stealer Log Breaches Work
These logs typically originate from infostealer malware that infects a device through pirated software, fake game cracks, or malicious email attachments. The malware harvests saved credentials straight out of the browser, packages them by site, and ships them off to a server controlled by criminals. Sellers then repackage the harvest under a cloud-themed name, like Nullcyber Cloud here, before distributing it through Telegram channels dedicated to buying and selling stolen data.
Check If You Are Affected
With 324,958 records already circulating from just this one file, it is worth taking two minutes to check your own exposure. HEROIC's free breach scanner searches over 400 billion compromised records, including stealer logs and ULP dumps like this one, so you can find out right away if your credentials need changing.
Breach Breakdown
324,958 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds