224,064 Stolen Passwords From the Xavier_Ulp Leak Surfaced Online
HEROIC analysts identified another file in the Xavier_Group series, this one labeled Xavier_Ulp - 346000, uploaded to a Telegram channel on 17 July 2026, just a day after a related batch from the same source. This release is larger than its predecessor, containing 224,064 records that pair email addresses with plaintext passwords and the exact login URLs where each credential was captured.
Why This Is Dangerous
A batch of this size hands an attacker more than 224,000 ready-to-use logins in a single download, complete with the site each one belongs to. There is no password cracking involved. The credentials are already in plaintext, so anyone with the file can immediately begin logging into real accounts across email, retail, and financial services.
What Was Exposed in the 346000 Batch
- Email addresses for 224,064 accounts
- Plaintext passwords paired with each address
- The login URLs where each credential was used
Why This Matters
The Xavier_Group series appears to be an ongoing operation, releasing successive Ulp files with growing record counts rather than a single one-off leak. That pattern matters because it signals a steady pipeline of freshly stolen credentials entering circulation. With 224,064 login pairs in this batch alone, attackers have more than enough volume to run large-scale credential stuffing attacks, and anyone who reuses passwords across sites faces a real risk of account takeover, identity theft, or financial fraud.
How Xavier_Group's Ulp Files Are Built
Ulp stands for User, Login, Password, a standard format for packaging stolen credentials into one clean, searchable file. These batches typically originate from stealer malware logs collected across many infected devices, then get merged, deduplicated, and formatted before being shared. The sequential numbering, 303451 in one release and 346000 in this one, suggests the group behind Xavier_Group is continuously processing new stolen data and pushing out fresh batches as they accumulate.
Check If You Are Affected
If your email address has ever been paired with a reused password anywhere online, batches like this one are exactly why checking matters now. HEROIC's free breach scanner searches your email against more than 400 billion leaked records, including every batch in series like Xavier_Group, so you can see if you are exposed and secure your accounts before someone else logs in first.
Breach Breakdown
224,064 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds