Act Now: Xavier_Ulp Breach Leaks 373,319 Passwords Online
On the very first day of 2026, another chunk of stolen data linked to Xavier_Ulp hit a Telegram channel. This time the stealer log carried 373,319 records, each one containing an email address, a plaintext password, and the web address the credentials belonged to.
Why This Is Dangerous
Unlike a leaked password list from an old forum, a fresh stealer log reflects what a person was logging into recently. The malware infection that produced this file likely occured sometime in December 2025 or earlier, meaning the credentials inside are still very much in use.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
- 373,319 records total
Why This Matters
Passwords stored in plaintext are the easiest kind of stolen data to abuse. There's no cracking, no guessing, just a seperate line item a criminal can copy directly into a login page and try their luck.
How Stealer Log Malware Works
Most stealer log infections trace back to a pirated software download or a "free" tool advertised on a forum or Discord server. Once installed, the malware scans the browser's saved password vault, siphons off session cookies, and sends the entire haul to a remote server controlled by the attacker.
Check If You Are Affected
HEROIC's free breach scanner checks your email against a database of 400 billion+ exposed records, including this Xavier_Ulp stealer log, so you can see right away if your information turned up and take action before someone else does.
Breach Breakdown
373,319 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds