100k UHQ USA Part 4 Leak: Stolen Logins Fuel Credential Stuffing Risk
In December 2022, HEROIC analysts identified a large stealer log dump uploaded to a public Telegram channel under the label "100k UHQ USA Part 4." The name signals a batch of "ultra high quality" credentials tied to US-based accounts, and this fourth installment alone contained 99,979 exposed records, each pairing an email address with a plaintext password and the login URL it unlocks.
Why This Is Dangerous
Nearly 100,000 working email and password combinations in one file is enough to run automated login attempts at scale. Because the passwords are stored in plaintext, an attacker does not need to crack or decrypt anything, they can plug the list straight into automated tools that quietly test each pair against hundreds of other websites within minutes of the file going public.
What Was Exposed in the 100k UHQ USA Part 4 Log
- 99,979 email addresses used as account logins
- Matching plaintext passwords for each email
- The login URL or endpoint each credential pair unlocks
Why This Matters: From One Leak to a Chain of Attacks
A single stolen login rarely stays contained. Attackers feed lists like this into credential stuffing tools that automatically try each email and password pair across banking, email, shopping, and social media sites, since so many people reuse the same password everywhere. A successful match on one site can hand an attacker access to a victim's inbox, which can then be used to reset passwords elsewhere, escalating a single leaked credential into full account takeover, financial fraud, and identity theft across multiple services.
How a Dump Like "100k UHQ USA Part 4" Gets Built
Stealer logs of this size are typically assembled from thousands of individually infected devices, each compromised by information-stealing malware hidden in pirated software, cracked games, or malicious downloads. The malware silently copies saved browser passwords and autofill data from each infected machine and reports back to the attacker. Sellers then sort, filter, and merge these logs into large "parts," like this one, labeling them by quality and country before releasing them piece by piece on Telegram.
Check If You Are Affected
With nearly 100,000 records in this batch alone, the odds that your email is included are real. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked and stolen records, including stealer logs like this one, so you can find out in seconds and take action before attackers do.
Breach Breakdown
99,979 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds