Plaintext, Not Hashed: SunCloudNew ULP Exposes 93,740 Logins
The SunCloudNew 1805 - 348 K ULP combolist, found circulating on Telegram in August 2026, held 93,740 email and password pairs, and every one of those passwords was stored in plaintext rather than hashed. That distinction matters more than the number itself, since scanning your email is how you find out if your plaintext password is now exposed.
Why Plaintext Changes Everything
A hashed password normally forces an attacker to spend time and computing power trying to crack it before it's usable. Plaintext skips that entirely. There's nothing to crack, nothing to guess, just a password sitting in the open ready to be typed into a login form.
What Was Exposed
- Email Addresses: identifies the account holder and gives attackers a target for phishing.
- Plaintext Password: stored as readable text, meaning it works immediately with zero extra effort.
- URLs: shows which site or service each credential pair was collected against.
What This Means for Anyone on the List
Since these passwords never needed to be cracked, they've likely already been tested against other sites the moment this file started circulating. Anyone whose password appears here should treat it as compromised right now, not as a future risk.
How a Plaintext Combolist Gets Built
Files like SunCloudNew 1805 - 348 K ULP are compiled from credentials that were already readable when they were collected, whether pulled from earlier leaks or infected devices, then merged together and shared as-is.
Check if Your Password Is Among the 93,740
Scan your email to find out. If you're listed, change that password immediately, on both personal and work accounts, since a plaintext credential is equally dangerous on either.
Breach Breakdown
93,740 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds