99,413 Plaintext Passwords Were Just Dumped on Telegram
In May 2023, a stealer log called UHQ Mix Part 1001 was posted to a public Telegram channel, exposing 99,413 records stolen from compromised devices. The dataset includes email addresses, plaintext passwords, and the URLs where each set of credentials was captured during active login sessions.
Why Plaintext Passwords Give Attackers an Instant Advantage
Every password in the UHQ Mix Part 1001 stealer log is stored in unencrypted, human-readable form. There are no hashes to crack, no encryption layers to bypass, and no additional steps between downloading the file and using the credentials to access accounts.
This gives threat actors an immediate and decisive advantage. Automated tools can ingest the full 99,413-record dataset and begin testing credentials against login pages across the internet within minutes. The speed of exploitation far outpaces most users' ability to discover and respond to the compromise.
Plaintext exposure also means that even complex, lengthy passwords offer no protection once they appear in a stealer log. Password strength is irrelevant when the actual password is already known.
What Was Exposed in the UHQ Mix Part 1001 Dump
- Email Addresses — Complete email addresses harvested from browser sessions, serving as both login usernames and direct channels for follow-up phishing attacks against the compromised individuals.
- Plaintext Passwords — Raw, unprotected passwords extracted from browser password stores and active sessions, ready for immediate use by any threat actor who obtains the file.
- URLs — The specific websites and login portals where credentials were stolen, giving attackers a precise map of which services can be accessed with each email-and-password pair.
Why Nearly 100,000 Leaked Credentials Pose a Serious Threat
With 99,413 records, the UHQ Mix Part 1001 log provides a substantial arsenal for credential-stuffing attacks. Cybercriminals use automated tools to take each email-and-password pair and test it against dozens or even hundreds of popular online services simultaneously, exploiting the widespread habit of password reuse.
Industry data suggests that credential-stuffing attacks succeed on roughly 0.1% to 2% of attempts. Applied to a dataset of this size, even the lowest success rate could yield hundreds of newly compromised accounts across banking, email, social media, and enterprise platforms.
The presence of URLs in the log makes these attacks even more efficient. Instead of testing credentials blindly, attackers can target the exact services where each password was originally used, dramatically increasing their success rate on the first attempt.
How Stealer Logs Move From Infected Devices to Telegram
The journey begins when a user unknowingly installs infostealer malware, often bundled with pirated software, delivered through phishing emails, or embedded in malicious browser extensions. The malware immediately begins extracting saved credentials, cookies, and session tokens from every browser installed on the device.
Each infected machine produces a structured log file containing every captured credential paired with its associated URL and email address. These individual logs are then aggregated by the threat actor or an intermediary into larger compilations like UHQ Mix Part 1001, which bundles logs from thousands of different infected devices into a single downloadable file.
The compiled dataset is then uploaded to Telegram, where it reaches a wide audience of opportunistic attackers who can immediately begin exploiting the stolen credentials. The "UHQ" designation, standing for "ultra-high quality," signals that the data has been curated or validated for accuracy.
Check If Your Credentials Were Exposed
The 99,413 credential sets in this stealer log were harvested from real devices used by real people. If you have ever saved a password in your browser or logged into an account from a device that could have been infected, there is a chance your data is included.
HEROIC offers a free breach scanner that checks your email and personal information against more than 400 billion records from data breaches, stealer logs, and dark web collections. Scanning takes only seconds and will show you whether your credentials appear in the UHQ Mix Part 1001 dump or in any of thousands of other known exposures.
If the scan reveals compromised credentials, act immediately: change the affected passwords, enable multi-factor authentication on all accounts, and run a thorough antivirus scan on your devices to ensure no active malware remains.
Breach Breakdown
99,413 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds