20k UHQ USA Basze Leak: Passwords Exposed Since March 2023
In March 2023, a Telegram user uploaded a stealer log dataset labeled "20k UHQ USA Basze," exposing 19,891 records tied to United States-based accounts. The file contains email addresses, plaintext passwords, and the URLs those credentials were used on, information pulled straight from malware-infected devices rather than a single company's servers.
Why a 2023 Leak Is Still a 2026 Problem
More than three years have passed since this data first surfaced, and that gap is exactly what makes it dangerous. Passwords rarely get changed on every account where they were reused, and stealer logs like this one are copied, resold, and recirculated on Telegram and dark web forums long after the original theft. If you have not changed a password since early 2023, there is a real chance a credential from this leak still works today.
What Was Exposed in the 20k UHQ USA Basze Leak
- Email addresses
- Plaintext passwords (stored and shared with no encryption)
- URLs showing which sites the credentials belonged to
Why This Matters for Anyone in This Data Set
Because the passwords in this leak are plaintext, anyone who obtains the file can use them immediately, with no cracking required. Attackers typically run these email-and-password pairs through automated tools against banking sites, email providers, and shopping accounts, a technique called credential stuffing. If you reused a password from 2023 anywhere else, that single leaked login can turn into a full account takeover, identity theft, or unauthorized charges on a linked payment method.
How Stealer Log Leaks Like This One Are Built
Stealer malware infects a device, usually through a fake download, cracked software, or malicious email attachment, and quietly copies saved passwords, autofill data, and browsing history straight out of the victim's browser. The malware bundles everything into a "log" and sends it back to whoever controls it. Criminals then combine thousands of these logs into files like "20k UHQ USA Basze" and share or sell them in Telegram channels, where anyone can download and use them.
Check If You Are Affected by This Leak
The only way to know for certain if your email address appears in this stealer log, or in any of the other breaches out there, is to check. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including stealer logs like this one, to tell you instantly if your information has been exposed. Run a free scan now and find out before someone else uses your data first.
Breach Breakdown
19,891 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds