Breach Intelligence Report 10 Apr 2026

The Nullcyber Cloud WordPress Breach Gave Hackers 3,387 Site Admin Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs ULP_Wordpress_6634_051025_144222_Nullcyber_Cloud uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 3,387
Source Type Stealer log
Origin United States
Password Type plaintext

In October 2025, HEROIC analysts confirmed a stealer log file distributed via Telegram under the filename "ULP_Wordpress_6634_051025_144222_Nullcyber_Cloud." The file exposed 3,387 records in URL-Login-Password format, with all URLs pointing to WordPress installations. The credentials include email addresses and plaintext passwords for WordPress admin panels and user accounts, making this dataset particularly valuable to attackers targeting website infrastructure rather than individual consumer accounts. The file was generated on October 5, 2025 and processed through the same Nullcyber Cloud infrastructure responsible for multiple concurrent stealer log releases.


Why WordPress Admin Credentials in This Stealer Log Give Attackers Total Site Control

WordPress powers more than 40 percent of all websites on the internet. A stealer log specifically sorted to contain WordPress credentials is not targeting individual user accounts. It is targeting website owners, developers, and administrators. An attacker who obtains a working WordPress admin password can immediately install malicious plugins, redirect visitor traffic to phishing pages, steal all user data from the site's database, deploy ransomware, or use the server as a platform for further attacks. Even non-admin WordPress user credentials are dangerous, as they can be used to post malicious content, inject scripts, or escalate privileges through known vulnerabilitiies. With 3,387 records in this file, the scale of potential website compromise is significant.


Data Exposed in the ULP Wordpress Nullcyber Cloud Stealer Log

The following data types were confirmed in this stealer log dataset:

  • Email Addresses — WordPress account login identifiers, many of which double as admin email addresses for recovery and notifications
  • Plaintext Passwords — captured in cleartext by malware, instantly usable against WordPress login pages without any processing
  • URLs — the specific WordPress login pages and sites from which credentials were harvested, enabling direct site targeting

What Attackers Can Do With 3,387 WordPress Credentials From This Breach

A dataset of WordPress-specific credentials enables a distinct set of attacks beyond typical consumer credential abuse:

  • Credential stuffing — automated tools test each pair against WordPress login pages and related CMS platforms at scale
  • Account takeover — successful admin logins allow attackers to change all user passwords, install backdoors, and lock out legitmate owners
  • Identity theft — WordPress user tables often contain full names, email addresses, and other personal data that can be extracted from the database
  • Financial fraud — WooCommerce stores running on compromised WordPress sites expose customer payment data and order history to the attacker

What Is the Nullcyber Cloud WordPress ULP Stealer Log and How Was It Created?

The Nullcyber Cloud WordPress ULP file is a regionally sorted subset of a larger stealer log operation. Threat actors who operate large-scale credential theft pipelines often sort their raw logs by platform type, creating targeted packages that are more valuable to buyers with specific attack goals. A WordPress-specific bundle like this one would be sold to or used by attackers who specialize in website takeover, black-hat SEO manipulation, spam email campaigns run through compromised sites, or cryptomining operations deployed on victim servers. The Nullcyber Cloud distribution network packages these bundles automaticaly from raw endpoint malware data and releases them through Telegram channels on a regular schedule, as evidenced by the timestamp-based filename.


Check If Your WordPress Credentials Were Exposed in This Breach with HEROIC's Free Scanner

HEROIC's breach scanner covers more than 400 billion compromised records, including WordPress-targeted stealer logs from the Nullcyber Cloud network and thousands of other datasets. If your email address or password appeared in this file, HEROIC will alert you immediately so you can rotate your credentials and secure your sites before an attacker gains access. Run a free scan today.

Breach Breakdown

Domain ULP_Wordpress_6634_051025_144222_Nullcyber_Cloud uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 10 Apr 2026
Check in 5 seconds

3,387 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,257 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $24.5K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance