LINE App Users Targeted in the BabaUlpNew Breach Exposing 90,287 Stolen Accounts
In October 2025, HEROIC analysts confirmed a stealer log file uploaded to Telegram under the name "BabaUlpNew 298 K ULP LINE 06.10.2025." The file exposed 90,287 records containing email addresses, plaintext passwords, and URLs, with a specific focus on LINE messaging app credentials. The dataset was compiled by a Telegram channel operator known as BabaUlp, which regularly publishes large credential bundles. The LINE-specific sorting indicates that the original stealer malware logs were filtered to extract high-value credentials from LINE users, a population concentrated in Japan, Thailand, Taiwan, and other Asian markets.
Why LINE App Users Are Specifically Targeted in This 90,287-Record Breach
LINE is one of the most widely used messaging and social platforms in Asia, with over 200 million active users. It functions not just as a chat app but as a payment platform, a business communication tool, and a social network. For attackers, a valid LINE credential represents access to private conversations, stored payment information, connected bank accounts through LINE Pay, and a trusted communications channel with the victim's personal and profesional contacts. A compromised LINE account can be used to impersonate the victim to their friends and family, request money transfers, or spread malware through trusted message threads. This makes LINE credentials especially valuble in criminal markets compared to generic website login pairs.
Data Exposed in the BabaUlpNew LINE ULP Stealer Log
The following data types were confirmed in this stealer log dataset:
- Email Addresses — account registration emails for LINE and associated services, used for phishing, account recovery abuse, and follow-on attacks
- Plaintext Passwords — captured in cleartext by information-stealing malware from infected devices, immediately usable without any decryption
- URLs — LINE login pages and related service URLs from which the credentials were harvested by stealer malware
How Attackers Use LINE Credentials From This Breach to Target Victims
Once stolen LINE credentials are in criminal hands, they power a range of highly targeted attacks:
- Credential stuffing — automated tools test each email and password pair against LINE and dozens of related platforms in rapid sucession
- Account takeover — attackers who access a LINE account change the phone number and recovery email to permanently lock out the real owner
- Identity theft — LINE accounts contain real names, profile photos, contact lists, and personal message history usable for social engineering and fraud
- Financial fraud — LINE Pay balances and linked bank accounts accessible through compromised LINE accounts are drained or used for unauthorized transactions
What Is BabaUlpNew and How Does It Distribute Stealer Logs on Telegram?
BabaUlp is the handle of a recurring Telegram channel operator known for publishing large, sorted stealer log bundles. The "New" designation in BabaUlpNew suggests an updated or rebranded channel, consistent with how Telegram-based credential distributors operate after channel removal and restart under new names. The 298 K in the filename refers to the claimed original file size, while the actual verified record count of 90,287 represents the deduplicated, processed output. BabaUlp-style distributors aggregate raw stealer logs from multiple sources, sort them by platform, region, or service type, and publish them in labeled bundles. These bundles are accessed by hundreds of channel subscribers within hours of posting, dramatically multiplying the number of attackers who hold this data and increasing the probability that individual victims will experience credential-based attacks on their accounts.
Protect Your LINE Account: Check Your Exposure with HEROIC's Free Breach Scanner
HEROIC's breach scanner searches more than 400 billion compromised records, including platform-specific stealer logs like this BabaUlpNew LINE dataset. If your email address or password appeared in this file or any other known breach, HEROIC will alert you immediately. Run a free scan today and find out if your LINE account credentials are already circulating among cybercriminals targeting Asian platform users.
Breach Breakdown
90,287 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds