U.S. Users Hit: Wrtcloud Exposes 122,064 Passwords
In March 2026, HEROIC identified a large-scale stealer log labeled ULP Wrtcloud PRIVATE 3-3-26 being distributed on Telegram. The file contains 122,064 records primarily affecting users in the United States, each comprising an email address, a plaintext password, and the associated URL. This is one of the larger individual stealer log dumps HEROIC has tracked, and its contents give attackers immediate access to over a hundred thousand accounts.
The Severity of Plaintext Password Exposure
All 122,064 passwords in this dump are in plaintext—completely unencrypted, unhashed, and immediately usable. An attacker does not need to invest time or resources in cracking these credentials. They can simply download the file and begin logging into accounts within seconds, making this one of the most actionable types of data a threat actor can obtain.
What Was Exposed
- Email Addresses — over 122,000 accounts vulnerable to takeover and phishing
- Plaintext Passwords — the actual passwords with no encryption layer
- URLs — the exact websites and services where credentials were harvested
Credential Stuffing at Scale
A dump of 122,064 credential pairs is a goldmine for credential stuffing operations. Attackers will feed this entire dataset into automated tools that test each combination across major banking institutions, email providers, social media platforms, and corporate login portals. With password reuse rates remaining high, a substantial fraction of these credentials will unlock additional accounts the victims never intended to expose.
Inside the Infostealer Supply Chain
The Wrtcloud stealer log was generated by infostealer malware deployed across a large number of infected devices. These trojans harvest saved credentials from web browsers, extract autofill data, and scrape login information from installed applications. The stolen data is aggregated into massive log files and uploaded to Telegram channels and underground marketplaces, where datasets of this size command significant attention from cybercriminal networks.
Check If Your Credentials Were Exposed
With over 122,000 records in this single dump, the likelihood of your information being included is significant. Use HEROIC's breach scanner, backed by more than 400 billion indexed records, to check whether your email address or domain appears in the Wrtcloud leak or any other breach. If your credentials are found, change them immediately across all services and enable two-factor authentication to prevent unauthorized access.
Breach Breakdown
122,064 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds