Breach Intelligence Report 19 Sep 2025

STARLINKCLOUD Stealer Log: 75,634 US Records and the September 2023 Cloud Cluster

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 75,634
Source Type Stealer log
Origin Telegram
Password Type plaintext

STARLINKCLOUD: 75,634 US Credentials and the September 29 Cluster's Largest Batch

The STARLINKCLOUD stealer log, uploaded to Telegram on September 29, 2023, is the largest dataset in a four-upload cluster that collectively exposed over 164,000 US credentials in a single day. At 75,634 records, STARLINKCLOUD's branding is almost certainly misdirection similiar to its STARLINKCLOUD2 and GODELESS CLOUD nameming convention siblings released the same day -- labels designed to evoke a well-known satellite internet provider and suggest the data contains high-value infrastructure credentials. The actual dataset follows the standard stealer log structure: plaintext passwords, endpoint URLs, and API host data harvested from infected US devices in a coordinated release event.


STARLINKCLOUD (September 2023): Breach Summary

  • Records Exposed: 75,634
  • Data Types: Email addresses, plaintext passwords, endpoint URLs, API host data
  • Breach Type: Stealer log
  • Password Type: Plaintext -- directly usable with no cracking required
  • Country: United States
  • Date Leaked: September 29, 2023

75,634 Plaintext Credentials: Instantly Actionable at Scale

With 75,634 credential records, STARLINKCLOUD is a substantial stealer log with the volume to sustain extended credential stuffing campaigns against high-value targets. Each of the 75,634 records pairs a plaintext password with a specific endpoint URL, eliminating the platform-guessing phase of credential attacks entirely. The endpoint URL data tells attackers exactly where each credential authenticates. For financial institutions, healthcare providers, and enterprise platforms appearing in the URL data, every matching record represents a direct, targeted account takeover attempt. At 75,634 records, the STARLINKCLOUD dataset provides sufficient volume for both automated bulk attacks and targeted manual exploitation of high-value accounts.


API Host Data and the Cloud Infrastructure Angle

The STARLINKCLOUD name may have been chosen because the API host component of this dataset could include cloud-adjacent infrastructure data. API host entries captured from infected US devices can reveal cloud provider API endpoints, developer tool configurations, and SaaS platform backend hosts. For a dataset branded with cloud imagery, the API host component may have been highlighted to potential buyers as evidence of cloud credential value. Whether or not the actual API host data skews toward cloud infrastructure, the impersonaion angle -- using a recognizable technology brand to inflate perceived value -- is a recurring tactic in stealer log distribution channels where buyer perception drives pricing.


The September 29, 2023 Cluster: 164,000 US Records in One Day

STARLINKCLOUD was released alongside STARLINKCLOUD2 (61,216 records), GODELESS CLOUD (6,986 records), and a date-named log (20,795 records) on September 29, 2023 -- a single-day coordinated upload event that collectively delivered over 164,000 US plaintext credential records to threat actor networks. This September 29 cluster predates the AuroraLogsTeam campaign's multi-batch release strategy by 18 months but follows the same operational pattern: multiple datasets, same distribution channel, same day. The STARLINKCLOUD dataset as the largest batch in this cluster represents the anchor release of the September 29 event, around which the smaller concurrent datasets were organized.


Check If Your Data Was Exposed

HEROIC's free breach scanner searches across more than 400 billion exposed records including stealer log data from the September 2023 STARLINKCLOUD cluster. If your credentials were among the 75,634 records in this dataset, they have been in active threat actor networks since September 2023. Search your email for free at HEROIC.com to see where your information has appeared.

Breach Breakdown

Domain N/A
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 19 Sep 2025
Check in 5 seconds

75,634 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,028 scanned today
Breach Rank #4,380 by affected users
Impact Score
3
sensitivity + scale + recency
Est. Financial Impact $547.3K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance