TOKYO CLOUD FREE10: 4,901 U.S. Passwords Posted Free on Telegram in February 2023
"FREE10" Means 10 Free Logs — and 4,901 Exposed Americans
The "FREE10" in this file name is a marketing label. It signals that the uploader is giving away 10 stealer log files at no charge, likely as a preview to attract buyers for larger paid collections. The TOKYO CLOUD operation posted this batch to Telegram on February 26, 2023, and inside those 10 files were 4,901 U.S. credential records, each with a plaintext password and the specific URL where the credentials were captured. HEROIC's DarkHive team confirmed the full dataset.
Free samples in the stealer log economy aren't charity. They're advertising. The people in this file are colateral damage from a threat actor trying to build their customer base.
What TOKYO CLOUD FREE10 Actually Exposed
Despite the casual framing of a "free" release, the data is serious. Every record in the file includes:
- Email Addresses: 4,901 U.S. accounts
- Plaintext Passwords: Cleartext, ready for immediate use
- Target URLs: The exact login pages where credentials were stolen
The Tokyo Cloud branding suggests the operator was attempting to build a recognizable channel identity in the Telegram stealer log ecosystem. Named operations like this are more persistent than one-off dumps: they have returning audiences, repeat releases, and in some cases subscription models. The "FREE10" format implies larger paid collections existed alongside this public release.
How Free Stealer Log Releases Amplify the Damage
Paid stealer log data typically circulates among a smaller pool of buyers on closed forums. When data is released publicly on Telegram for free, the audience expands massivly. Anyone in that channel, which may have thousands of subscribers, can download it instantly. The result is that the 4,901 people in this file were exposed not to one attacker but potentially to thousands.
Each person in the file faces the same core risk: their email and plaintext password combination is in circulation, tied to a specific login URL, and has been testable against any other service they used that password on since February 2023. Credential stuffing, account takeover, identity theft, and financial fraud are all downstream possibilities.
See If Your Email Is in the TOKYO CLOUD Dataset
HEROIC's breach database, now covering more than 400 billion records, includes this and similar Telegram stealer log releases. Their free scanner checks any email against the full dataset in seconds. If your credentials appeared in the TOKYO CLOUD FREE10 file or any related dump, you'll know immediately and can take steps to protect the accounts involved.
Breach Breakdown
4,901 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds