Search Your Email: The S COUNTRY DIAMOND Dump Exposed 1,748 Accounts
The S COUNTRY - 160PCS DIAMOND_logscloud stealer log has been circulating in criminal hands since June 2023. It contains 1,748 plaintext passwords, email addresses, and login URLs stripped directly from the browsers of infected devices by credential-harvesting malware. The data was uploaded to Telegram by a threat actor and quickly distributed across private criminal channels. Most of the 1,748 people in this dump have no idea they were ever compromised. Their passwords were taken silently, without any alert, error message, or visible sign on their devices. The only way to know if you are in this file is to check -- and HEROIC makes that free.
Why This Is Dangerous
Stealer log data ages differently from traditional breach data. When a hashed password database leaks, attackers must crack the hashes first -- a process that can take days, weeks, or never succeed for strong passwords. With stealer logs, there is nothing to crack. Every one of the 1,748 passwords in the S COUNTRY dump is in plaintext, exactly as the victim typed or saved it. Criminals can use them immediately for account takeover, credential stuffing, and targeted fraud. The URLs in the log reveal which platforms each victim was authenticated to at the moment of infection, giving attackers a precice roadmap of where to attack first. Three years after this dump was first uploaded, the data is still actively traded and used.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs (active authenticated sessions captured at time of device infection)
Why This Matters
The S COUNTRY - 160PCS DIAMOND_logscloud dump was assembled from 160 individual device infection logs -- 160 separate people whose machines were silently comprimised by infostealer malware. Those 160 infection logs yielded 1,748 total credential records, meaning each infected device typically had multiple accounts saved. Every account in every browser on every infected device was captured. If you changed your email provider or banking password since June 2023 but kept using the same password elsewhere, those other accounts remain exposed. Dark web data doesn't expire. This dump will contineu to circulate in criminal communities for years to come.
How Stealer Log Breaches Work
Infostealer malware is one of the most efficient tools in the modern cybercriminal's arsenal. It arrives through phishing emails, fake software cracks, malicous browser extensions, or trojanized downloads. Once running on a victim's device, it systematically extracts all saved browser passwords, active session cookies, autofill data, and cryptocurrency wallet credentials. The entire haul is compressed into a log file and transmitted silently to the attacker's command infrastructure -- often a Telegram bot that automatically sorts and packages the data. The S COUNTRY collection represents 160 such successful device compromises merged into a single distributable file. None of the 1,748 affected individuals recieved any notification. The malware completed its mission invisibly and moved on.
Check If You Are Affected
Do not guess whether your email is in this dump -- find out for certain. HEROIC's free breach scanner searches more than 400 billion exposed records, including the S COUNTRY - 160PCS DIAMOND_logscloud stealer log. Enter your email address at HEROIC and get an instant, definitive answer. If your credentials appear in this file, HEROIC will show you exactly what was leaked -- which passwords, which accounts, which platforms -- and walk you through the steps to secure everything before an attacker uses the data against you. The scan is free, takes seconds, and requires no account creation. Search your email now.
Breach Breakdown
1,748 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds