Breach Intelligence Report 10 Apr 2026

LINE App Users Targeted in the BabaUlpNew Breach Exposing 90,287 Stolen Accounts

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs BabaUlpNew 298 K ULP LINE 06.10.2025 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 90,287
Source Type Stealer log
Origin United States
Password Type plaintext

In October 2025, HEROIC analysts confirmed a stealer log file uploaded to Telegram under the name "BabaUlpNew 298 K ULP LINE 06.10.2025." The file exposed 90,287 records containing email addresses, plaintext passwords, and URLs, with a specific focus on LINE messaging app credentials. The dataset was compiled by a Telegram channel operator known as BabaUlp, which regularly publishes large credential bundles. The LINE-specific sorting indicates that the original stealer malware logs were filtered to extract high-value credentials from LINE users, a population concentrated in Japan, Thailand, Taiwan, and other Asian markets.


Why LINE App Users Are Specifically Targeted in This 90,287-Record Breach

LINE is one of the most widely used messaging and social platforms in Asia, with over 200 million active users. It functions not just as a chat app but as a payment platform, a business communication tool, and a social network. For attackers, a valid LINE credential represents access to private conversations, stored payment information, connected bank accounts through LINE Pay, and a trusted communications channel with the victim's personal and profesional contacts. A compromised LINE account can be used to impersonate the victim to their friends and family, request money transfers, or spread malware through trusted message threads. This makes LINE credentials especially valuble in criminal markets compared to generic website login pairs.


Data Exposed in the BabaUlpNew LINE ULP Stealer Log

The following data types were confirmed in this stealer log dataset:

  • Email Addresses — account registration emails for LINE and associated services, used for phishing, account recovery abuse, and follow-on attacks
  • Plaintext Passwords — captured in cleartext by information-stealing malware from infected devices, immediately usable without any decryption
  • URLs — LINE login pages and related service URLs from which the credentials were harvested by stealer malware

How Attackers Use LINE Credentials From This Breach to Target Victims

Once stolen LINE credentials are in criminal hands, they power a range of highly targeted attacks:

  • Credential stuffing — automated tools test each email and password pair against LINE and dozens of related platforms in rapid sucession
  • Account takeover — attackers who access a LINE account change the phone number and recovery email to permanently lock out the real owner
  • Identity theft — LINE accounts contain real names, profile photos, contact lists, and personal message history usable for social engineering and fraud
  • Financial fraud — LINE Pay balances and linked bank accounts accessible through compromised LINE accounts are drained or used for unauthorized transactions

What Is BabaUlpNew and How Does It Distribute Stealer Logs on Telegram?

BabaUlp is the handle of a recurring Telegram channel operator known for publishing large, sorted stealer log bundles. The "New" designation in BabaUlpNew suggests an updated or rebranded channel, consistent with how Telegram-based credential distributors operate after channel removal and restart under new names. The 298 K in the filename refers to the claimed original file size, while the actual verified record count of 90,287 represents the deduplicated, processed output. BabaUlp-style distributors aggregate raw stealer logs from multiple sources, sort them by platform, region, or service type, and publish them in labeled bundles. These bundles are accessed by hundreds of channel subscribers within hours of posting, dramatically multiplying the number of attackers who hold this data and increasing the probability that individual victims will experience credential-based attacks on their accounts.


Protect Your LINE Account: Check Your Exposure with HEROIC's Free Breach Scanner

HEROIC's breach scanner searches more than 400 billion compromised records, including platform-specific stealer logs like this BabaUlpNew LINE dataset. If your email address or password appeared in this file or any other known breach, HEROIC will alert you immediately. Run a free scan today and find out if your LINE account credentials are already circulating among cybercriminals targeting Asian platform users.

Breach Breakdown

Domain BabaUlpNew 298 K ULP LINE 06.10.2025 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 10 Apr 2026
Check in 5 seconds

90,287 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,693 scanned today
Breach Rank #4,176 by affected users
Impact Score
4
sensitivity + scale + recency
Est. Financial Impact $653.3K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance