Researchers Spot SunCloudNew Part04 With 22,578 Logins Live
Researchers tracking the SunCloudNew campaign spotted part04 on Telegram June 9, 2026, carrying another 22,578 stolen logins.
Why This Is Dangerous
Part04 continues the same pattern as the rest of the series, plaintext passwords with zero protection, collected from an ongoing malware operation targeting a large number of devices.
What Was Exposed
- Email addresses (22,578 unique accounts)
- Plaintext passwords with no encryption
- URLs tied to each compromised service
Why This Matters
As more parts of this campaign come to light, the overall picture gets clearer, this is a large, sustained operation rather than a single small leak. Every additional part means more people whose accounts are now at risk.
How Stealer Logs Work
The pattern researchers see with campaigns like SunCloudNew is straightforward, malware infects a device, copies every saved password, and reports back to the operator, who releases the accumulated data in numbered batches. Part04 likely represents victims infected around the same general timeframe as parts 03 and 05.
Check If You Are Affected
HEROIC's free scanner checks your email against more than 400 billion (400B+) leaked records, covering every part of the SunCloudNew series. Don't wait for researchers to flag your specific account, run the check yourself and change any exposed passwords right away, it's definately faster than waiting to recieve bad news later.
Breach Breakdown
22,578 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds