Search Your Email: The Cracked 45.9M ULP Dump Exposed 10.9 Million Accounts
On December 5, 2024, a stealer log titled "45.9M ULP" was posted on Cracked, a popular hacking forum, by a threat actor operating as "MulaBhai." The raw file contained approximately 46 million lines. After deduplication, analysts identified 10,928,936 unique compromised records. Each record pairs an email address with a plaintext password and the URL of the website where the credential was originally captured by infostealer malware. With nearly 11 million ready-to-use email-password pairs now circulating in criminal communities, this is one of the larger stealer log dumps indexed from that period.
Why This Is Dangerous
A stealer log of this size is not merely a data exposure event. It is a pre-built weapon for credential stuffing campaigns. Because every password in this dump is stored in plaintext and paired with the exact site URL it was stolen from, attackers do not need any additional processing to begin attacks. They can immediately load this data into automated tools and begin testing logins across email providers, banks, retail platforms, and social networks. The 10.9 million unique records represent 10.9 million attack opportunities, each tied to a real person's real account.
What Was Exposed
The Cracked 45.9M ULP by MulaBhai stealer log exposed the following data types for 10,928,936 unique records:
- Email Address
- Plaintext Password
- HomePage URL (the specific site each credential was stolen from)
Why This Matters
The combination of email, plaintext password, and source URL unlocks a full chain of downstream attacks:
- Credential stuffing: Each pair is immediately testable across every major online platform. No hash cracking is required.
- Account takeover: Password reuse is widespread. A single exposed credential can unlock banking, email, shopping, and social media accounts all at once.
- Identity theft: Gaining access to an email account gives attackers the ability to intercept password resets and seize control of every linked account.
- Fraud: Access to financial or e-commerce accounts enables unauthorized purchases, fund transfers, and gift card fraud.
- Targeted phishing: Knowing the site a password was stolen from makes follow-up impersonation emails far more believable and effective.
How Stealer Log Leaks Work
The "45.9M ULP" log originates from infostealer malware, software designed to silently extract credentials saved in web browsers on infected computers. Malware families such as RedLine Stealer, Vidar, Raccoon, and Lumma Stealer infect devices through phishing attachments, fake software downloads, pirated content, and malicious ads. Once active, they harvest stored logins and transmit them to attacker-controlled servers in ULP format: URL, login, and password in structured text. These logs are then compiled, sorted for uniqueness, and distributed on criminal forums like Cracked. The title "45.9M ULP" refers to the total line count of the raw file, while the 10.9 million figure reflects the number of unique, usable credentials after duplicate removal.
Check If You Are Affected
Your email address and password could be in this dump even if you have never visited a suspicious website, as stealer malware often infects devices through seemingly legitimate software. Heroic's breach search database indexes over 400 billion compromised records, including major stealer log dumps like this one.
Search your email at Heroic now to instantly find out whether your credentials appear in the Cracked 45.9M ULP dump by MulaBhai or in any of the thousands of other known breach data sets in our database.
Breach Breakdown
10,928,936 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds