Nullcyber Cloud ULP Dump Exposed 34,223 Login Credentials
A file called ULP_09_10_2025Nullcyber_Cloud showed up on Telegram in October 2025. It contained 34,223 records. Each one paired an email adress with a plaintext password and a URL.
Why This Is Dangerous
This is not complicated data to use. A criminal opens the file, sees a password sitting in plain text, and tries it on the matching website. No cracking. No guessing. Just a login and a password ready to go. Anyone who reused that password on another account handed over more than they realize.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs linking each credential to its source site
- 34,223 total records exposed
Why This Matters
34,223 people did not choose to have their credentials posted online. Their devices were infected, their browsers were scraped, and the results ended up in a Telegram channel with no warning. Most of them still don't know it happened. That is the whole problem with stealer logs, wich almost always surface long after the damage is already done.
How Stealer Logs Work
Stealer malware infects a device through a bad download, a cracked program, or a malicious link. It runs quietly in the background. It copies saved passwords, cookies, and browser data. It sends everything back to whoever controls it. That person can recieve dozens of these logs a week, then package and post them exactly like this one.
Check If You Are Affected
Checking your exposure takes less time than reading this article. HEROIC runs a free breach scanner against more than 400 billion leaked records. Enter your email, see the results, and change any password that shows up as compromised.
Breach Breakdown
34,223 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds