The Nullcyber Cloud WordPress Breach Gave Hackers 3,387 Site Admin Credentials
In October 2025, HEROIC analysts confirmed a stealer log file distributed via Telegram under the filename "ULP_Wordpress_6634_051025_144222_Nullcyber_Cloud." The file exposed 3,387 records in URL-Login-Password format, with all URLs pointing to WordPress installations. The credentials include email addresses and plaintext passwords for WordPress admin panels and user accounts, making this dataset particularly valuable to attackers targeting website infrastructure rather than individual consumer accounts. The file was generated on October 5, 2025 and processed through the same Nullcyber Cloud infrastructure responsible for multiple concurrent stealer log releases.
Why WordPress Admin Credentials in This Stealer Log Give Attackers Total Site Control
WordPress powers more than 40 percent of all websites on the internet. A stealer log specifically sorted to contain WordPress credentials is not targeting individual user accounts. It is targeting website owners, developers, and administrators. An attacker who obtains a working WordPress admin password can immediately install malicious plugins, redirect visitor traffic to phishing pages, steal all user data from the site's database, deploy ransomware, or use the server as a platform for further attacks. Even non-admin WordPress user credentials are dangerous, as they can be used to post malicious content, inject scripts, or escalate privileges through known vulnerabilitiies. With 3,387 records in this file, the scale of potential website compromise is significant.
Data Exposed in the ULP Wordpress Nullcyber Cloud Stealer Log
The following data types were confirmed in this stealer log dataset:
- Email Addresses — WordPress account login identifiers, many of which double as admin email addresses for recovery and notifications
- Plaintext Passwords — captured in cleartext by malware, instantly usable against WordPress login pages without any processing
- URLs — the specific WordPress login pages and sites from which credentials were harvested, enabling direct site targeting
What Attackers Can Do With 3,387 WordPress Credentials From This Breach
A dataset of WordPress-specific credentials enables a distinct set of attacks beyond typical consumer credential abuse:
- Credential stuffing — automated tools test each pair against WordPress login pages and related CMS platforms at scale
- Account takeover — successful admin logins allow attackers to change all user passwords, install backdoors, and lock out legitmate owners
- Identity theft — WordPress user tables often contain full names, email addresses, and other personal data that can be extracted from the database
- Financial fraud — WooCommerce stores running on compromised WordPress sites expose customer payment data and order history to the attacker
What Is the Nullcyber Cloud WordPress ULP Stealer Log and How Was It Created?
The Nullcyber Cloud WordPress ULP file is a regionally sorted subset of a larger stealer log operation. Threat actors who operate large-scale credential theft pipelines often sort their raw logs by platform type, creating targeted packages that are more valuable to buyers with specific attack goals. A WordPress-specific bundle like this one would be sold to or used by attackers who specialize in website takeover, black-hat SEO manipulation, spam email campaigns run through compromised sites, or cryptomining operations deployed on victim servers. The Nullcyber Cloud distribution network packages these bundles automaticaly from raw endpoint malware data and releases them through Telegram channels on a regular schedule, as evidenced by the timestamp-based filename.
Check If Your WordPress Credentials Were Exposed in This Breach with HEROIC's Free Scanner
HEROIC's breach scanner covers more than 400 billion compromised records, including WordPress-targeted stealer logs from the Nullcyber Cloud network and thousands of other datasets. If your email address or password appeared in this file, HEROIC will alert you immediately so you can rotate your credentials and secure your sites before an attacker gains access. Run a free scan today.
Breach Breakdown
3,387 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds