24,322 Slurm HPC Cluster Credentials Leaked via Telegram in April 2025
In April 2025, DarkHive identified a stealer log file uploaded to Telegram by the Slurm Logs | Free logs channel, exposing 24,322 records harvested from compromised endpoints across the United States. The log contained email addresses, plaintext passwords, and service URLs, with the data appearing to originate from compromised developer and system administrator accounts associated with Slurm workload management environments. The Slurm Logs series represents a recurring Telegram-based stealer log campaign that targets computing infrastructure endpoints. The breach date was recorded as April 21, 2025.
Why This Is Dangerous
Slurm is widely deployed across academic research institutions, scientific computing clusters, and enterprise HPC environments. Credentials from these systems give attackers access to significant computational resources that can be repurposed for cryptomining, model training, or further network infiltration. When email addresses and plaintext passwords from Slurm environments are released freely on Telegram, any subscriber can attempt to aquire unauthorized access to these high-value systems. The inclusion of service URLs further reduces the effort required to identify and exploit vulnerable endpoints.
What Was Exposed
- Email addresses
- Plaintext passwords
- Service and API host URLs
Why This Matters
Computing cluster credentials are among the most valuable stolen assets for certain categories of attackers, particularly those running large-scale AI training operations or cryptocurrency mining campaigns. Beyond resource theft, access to HPC environments can expose sensitive research data, proprietary algorithms, and scientific datasets. The plaintext nature of the passwords in this log means no cracking step is needed; victims remain at risk until they change thier passwords or administrators force a reset across affected accounts.
How Stealer Log Infections Work
Infostealer malware is typically spread through phishing emails targeting developers and researchers, malicious software packages distributed via package managers, and trojanized productivity tools. Once executed, the malware silently captures credentials stored in browsers and application configuration files before transmitting the data to attacker-controlled servers or Telegram bots. The collected records are then organized and released as named log files, with the Slurm Logs campaign specifically labeling files to signal their relevance to computing infrastructure targets. Victims typicaly have no indication that thier credentials were captured until unauthorized access is detected.
Check If You Are Affected
HEROIC offers a free identity scanner that searches over 400 billion records, including data from stealer logs like Slurm Logs SlurmLogs. Visit heroic.com to scan your email address and find out if your information was exposed.
Breach Breakdown
24,322 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds