U.S. Accounts Targeted in the TOKYO CLOUD FREE91 Stealer Log Dump
HEROIC analysts identified a stealer log named TOKYO CLOUD FREE91 that a Telegram user uploaded, containing 4,263 records of email addresses, plaintext passwords, and the URLs those credentials were used on. The underlying data was captured back in July 2024 and is tagged to accounts located in the United States, meaning U.S. users make up the population affected by this particular dump.
Why This Is Dangerous
Stealer logs capture whatever a piece of malware finds saved in a browser at the time of infection, so the passwords in TOKYO CLOUD FREE91 are stored in plaintext with nothing to decrypt. Anyone who gets hold of the file can go straight to the listed URLs and log in using the paired email and password, exactly as the real account holder would. No cracking, guessing, or additional effort is required.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs (the login pages tied to each credential)
Why This Matters
For the 4,263 people in this dump, the practical risk comes down to password reuse. If the password captured by the stealer malware is still in use anywhere else, an attacker can use it to break into email, banking, or shopping accounts well beyond the original site listed in the log. Because this data was collected in 2024 and only surfaced publicly now, some of the accounts involved may still be using the exact same password today, making credential stuffing attacks against U.S. targets a realistic follow-on risk.
How Stealer Logs Work
A stealer log is generated by information-stealing malware that infects a device and copies out saved browser passwords, autofill entries, and other stored credentials, then sends everything back to whoever controls the malware. Victims rarely realize an infection happened, since stealers are designed to run quietly in the background. Once collected, logs like TOKYO CLOUD FREE91 are packaged and distributed on Telegram and dark web forums, sold or shared as a batch tied to whichever devices the malware managed to infect, not to any single company being breached.
Check If You Are Affected
To find out if your email address appears in TOKYO CLOUD FREE91 or any other stealer log, run a free scan with HEROIC's breach checker. It searches a database of more than 400 billion compromised records, giving you a quick way to see if your credentials need to change.
Breach Breakdown
4,263 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds