The Primo_Cloud Dump Exposed 28,665 US Accounts and Passwords
In February 2026, HEROIC analysts found a stealer log file labeled TELEGRAM-Primo_Cloud - 2K Pcs -28_2Tv19 uploaded to a Telegram channel by an anonymous user. The file contained 28,665 records, each pairing an email address with a plaintext password and the URL of the login page it worked on. The records are tagged as belonging to United States accounts, making this a dump primarily affecting US-based internet users.
Why This Is Dangerous
Nearly 29,000 US accounts had their login credentials copied straight out of an infected browser and posted for anyone to download. Because the passwords are stored in plaintext, there is no barrier between an attacker downloading this file and using the credentials immediately. Anyone in this dataset could have someone else quietly signing into their accounts right now.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the associated login pages
Why This Matters
A leak of nearly 29,000 accounts gives attackers a large enough sample to run automated credential stuffing campaigns targeting US consumers specifically. Because password reuse is common, a single stolen login can be tested against email providers, banks, and retailers until one works, opening the door to account takeover, identity theft, and direct financial fraud for the people affected.
How the Primo_Cloud Dump Exposed These US Accounts
This file was generated by infostealer malware, which infects a device through phishing emails, pirated downloads, or malicious ads and then quietly extracts every saved password from the browser. The results were organized into a batch labeled "2K Pcs," referring to roughly two thousand infected devices, and then bundled together and posted to Telegram, where the full 28,665-record file became available to anyone looking for stolen US credentials.
Check If You Are Affected
If you are a US-based internet user and have ever had malware on your device, your credentials could be part of this leak. HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including the Primo_Cloud dump, so you can quickly see if you're affected and secure your accounts.
Breach Breakdown
28,665 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds