SunCloudNew Part07 Leak Hits 30,778 Cloud Service Accounts
A second SunCloudNew stealer log, this one labeled part07, appeared on Telegram June 9, 2026, carrying 30,778 fresh email and password pairs pulled straight from infected machines.
Why This Is Dangerous
Just like its companion files, this log stores every password in plain text. There's no encryption standing between an attacker and a working login, they just open the file and start testing accounts.
What Was Exposed
- Email addresses (30,778 unique accounts)
- Plaintext passwords with no encryption
- URLs tied to each compromised service
Why This Matters
When the same source uploads multiple parts back to back, it usually means the malware operation is large and definately ongoing. If your email turns up in one part, it's worth checking whether you appear in the others too, since attackers often split massive logs into smaller files just to make them easier to share.
How Stealer Logs Work
These multi-part logs come from stealer malware running on many infected computers at once. As the malware collects credentials, operators split the growing pile into numbered files, like part06, part07, part08, and release them in batches rather than dumping everything at once.
Check If You Are Affected
HEROIC has cataloged over 400 billion (400B+) exposed records, including entries from every SunCloudNew part release. Run your email through HEROIC's free scanner to find out if you were caught up in this one, and change any passwords that come back exposed right away, it's neccessary even if the account seems unimportant.
Breach Breakdown
30,778 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds