279,776 Records Exposed in SunCloudNew 1653 Stealer Log Leak
When a Telegram channel dedicated to trading stolen data posted a file labeled "SunCloudNew 1653," the number in the name told its own story. This was the 1,653rd release in an ongoing series from the same source, and this single batch alone held 279,776 records of stolen logins. It surfaced on March 22, 2026, and copies of it are still circulating on dark web forums today.
Why This Is Dangerous
A number like 279,776 can feel abstract until you consider what it actually represents: real people who typed a password into a login box, never knowing malware was quietly copying it in the background. Every one of those records includes a plaintext password, meaning whoever downloads this file doesn't need to crack, guess, or brute-force anything. The credentials are ready to use the moment they open the file.
What Was Exposed
- Email addresses tied to real user accounts
- Passwords stored in plaintext, with zero encryption protecting them
- URLs showing exactly which websites and services each login unlocks
Why This Matters
Because the URLs are bundled right alongside the usernames and passwords, an attacker doesn't have to guess where to use them. They can go straight to a banking portal, an email inbox, or a work login page and try the exact credentials that were harvested. If you happen to reuse a password across more than one account, one leaked login can unlock several doors at once, not just the one it was stolen from.
How Stealer Logs Work
This particular file falls under what security researchers call a "stealer log," and it comes from a very different process than a company getting hacked. Instead, malware gets installed on someone's personal computer, often through a cracked piece of software, a fake download, or a malicious email attachment. Once it's running, the malware quietly reaches into the browser's saved password vault and copies out every login stored there, then packages everything into a text file and sends it back to whoever controls the malware. It doesn't take long, and the victim usually has no idea it occured.
Check If You Are Affected
You shouldn't have to wonder whether your email showed up in a file like this one. HEROIC's free scanner checks your address against a database of more than 400 billion (400B+) leaked records pulled from breaches and stealer logs just like this one, and it takes less than a minute to get an answer. If your details do turn up, changing that password imediately and turning on two-factor authentication is the fastest way to shut the door before anyone walks through it.
Breach Breakdown
279,776 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds