Our Analysts Found the ArtHouse Cloud Logs v3 Dump on Telegram
HEROIC analysts found a dump called "ArtHouse Cloud Logs v3" circulating on Telegram in August 2026, part of the same series as an earlier "v2" release tracked separately. This batch contains 18,344 records harvested by stealer malware, including email addresses, plaintext passwords, and the URLs each login belongs to.
Why This Is Dangerous
Because this data comes from a stealer log rather than an old breach, the 18,344 credentials in this file reflect passwords that were active and saved in a browser at the moment of infection. That makes them more likely to still work than credentials pulled from a years-old leak.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs for each captured login
Why This Matters
Active, currently-used credentials raise the risk of account takeover for anyone in this dump, and any password reused elsewhere extends that risk to other accounts through credential stuffing. The fact that this is the third version in a series also suggests an ongoing malware campaign continuing to harvest new victims.
How This Stealer Log Series Was Built
Stealer malware infects devices, commonly through cracked software or malicious downloads, then quietly copies saved browser passwords and the sites they belong to before sending the data back to the operator. The operator behind "ArtHouse Cloud Logs" appears to be releasing these batches in sequence, with v3 following v2 as new infections generate new data.
Check If You Are Affected
Search HEROIC's free breach scanner, covering more than 400 billion leaked records, and if your email shows up, change your passwords and run a malware scan on your devices right away.
Breach Breakdown
18,344 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds