1,052,299 Records Leaked in UrlLogPass Stealer Log Dump
1,052,299 records is the final count on UrlLogPass-yahyawrt, a stealer log dump that has been sitting on Telegram since it was uploaded back on January 2, 2026, quietly accumulating downloads for months.
Why This Is Dangerous
Crossing the million record mark puts this leak in a different category entirely, since files this large tend to get picked up by multiple groups and recirculated across dozens of channels and forums, definately spreading well beyond its original upload point.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs for each login
The file totals 1,052,299 records, each one linking an email address to its password and the site it was captured from.
Why This Matters
This leak occured months ago, which means anyone caught in it has had plaintext passwords exposed untill now without knowing it. The longer a file like this circulates, the more chances attackers get to test the credentials against fresh targets.
How Stealer Logs Work
UrlLogPass style dumps get their name from the exact format they use, listing the URL, login, and password together for each captured account. That format comes straight from how info stealing malware records data as it scrapes browsers on infected devices, making it simple for attackers to load straight into automated login tools.
Check If You Are Affected
With a file this size and this old, checking your exposure is more important than ever. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, so you can find out in seconds if you are one of the 1,052,299 people caught in this leak.
Breach Breakdown
1,052,299 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds