108,116 Stolen Passwords From the UP_DaisyCloud Log Are Now on Telegram
HEROIC analysts tracking dark web Telegram channels flagged a significant credential dump on June 11, 2025. The log, circulated under the name UP_DaisyCloud 6412 through the .boxed.pw distribution channel, exposed 108,116 records pulled directly from infected user machines. Each record contained a real email address, the account password in plaintext, and the homepage URL of the site those credentials belonged to. This is not a corporate database breach. This is stealer malware doing exactly what it was designed to do: silently harvest everything stored in your browser and hand it to strangers on the internet.
Why Plaintext Passwords From the UP_DaisyCloud Log Are Especially Dangerous
Most data breaches expose hashed passwords, which at least require some effort to crack. This log contains none of that protection. Every password in the UP_DaisyCloud dump is readable as-is, the same way you type it. That means anyone who downloaded this file, and these Telegram channels have thousands of subscribers, can immediately log into any account where that password is still active. No cracking tools. No waiting. Just copy, paste, and in.
The homepage URLs make things worse. Instead of guessing which sites to target, an attacker already knows exactly which service each credential belongs to. That turns 108,000 records into 108,000 ready-to-use login attempts against specific, identified targets.
What Was Exposed in the UP_DaisyCloud Stealer Log
- Email addresses tied to real user accounts
- Plaintext passwords with no encryption or hashing
- HomePage URLs identifying the exact site each credential was stolen from
Why This Matters Beyond the 108,000 Affected Accounts
People reuse passwords. That is the uncomfortable truth that makes stealer logs so valuable to criminals. If your email and password from one site appear in this log, every other account where you used that same password is also at risk. Attackers run these credentials through a process called credential stuffing, where automated tools test stolen logins against banks, email providers, social media platforms, and retail sites, all at once.
Account takeover is the immediate threat. Identity theft and financial fraud follow closely. Once an attacker is inside your email account, they can reset passwords on every other service tied to that address, locking you out of your own digital life while they drain whatever value they can find.
How Stealer Log Breaches Like UP_DaisyCloud Actually Work
A stealer log is the output of infostealer malware, a category of malicious software designed to quietly run on a victim's computer and extract credentials saved in browsers, email clients, and apps. Programs like RedLine, Vidar, and Raccoon Stealer are commonly sold as subscription services on dark web forums, making them accessable to even low-skill attackers.
Once the malware runs on a device, it packages everything it finds into a structured log file and sends it back to the operator. Those operators then bundle hundreds or thousands of logs together and distribute them on platforms like Telegram, sometimes for profit, sometimes just for reputation. The result is what you see here: over 100,000 real people's credentials, freely posted and downloadable by anyone who knows where to look.
What makes this partcularly troubling is that the victim usually has no idea anything happened. There is no notification, no breach announcement from a company. The malware runs silently and disappears.
Check If Your Email Appeared in the UP_DaisyCloud Dump
HEROIC maintains a breach intelligence database of over 400 billion records, including stealer logs like this one. If your email address appeared in the UP_DaisyCloud log or any other known breach, HEROIC's free scanner will tell you, along with what specific data was exposed.
Run a free scan at heroic.com. It takes about 30 seconds and you do not need to create an account to get your results. If your credentials are out there, knowing is the first step to locking things down.
Breach Breakdown
108,116 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds