Dark Web Intel: 4.6 Million Plaintext Passwords From CrakolCloud 18M ULP Leaked on Telegram
HEROIC analysts flagged a large credential dataset distributed through a public Telegram channel on January 25, 2025. The collection, posted under the name CrakolCloud 18M ULP by crakol, contained approximately 18 million lines of data structured in URL:Login:Password format, a common layout used for credential stuffing attacks. After deduplication, the dataset included 4.6 million unique email addresses, each paired with a plaintext password and the URL of the site where that credential was used. This is not a single-site breach. It is a compiled harvest from many compromised accounts, aggregated and published for mass exploitation.
Why Plaintext Passwords Distributed on Telegram Are an Immediate Threat
Most breaches expose hashed passwords, which require time and computing power to crack. This dataset is different. Every password in the CrakolCloud 18M collection is already in plaintext, meaning anyone who downloaded it could immediately try those credentials on any website. Combined with the homepage URLs included in each record, attackers already know which sites to target. If you reuse passwords across accounts, a single compromised credential in this dataset could unlock your email inbox, cloud storage, banking portal, or workplace tools within minutes of the file being downloaded.
What Was Exposed in the CrakolCloud 18M ULP Collection
- Email addresses (4.6 million unique accounts)
- Plaintext passwords
- Homepage URLs indicating which services were targeted
The URL:Login:Password format makes this dataset plug-and-play for credential stuffing tools. Attackers do not need to do any additional processing. They load the file into an automation tool and begin testing logins across hundreds of platforms simultaneously.
Why This Matters: From Credential Stuffing to Account Takeover
Credential stuffing is the automated process of testing stolen username and password pairs against login pages at scale. It works because most people reuse passwords. A single valid pair from a list like CrakolCloud can unlock accounts on unrelated platforms, giving attackers access to email, financial accounts, and workplace systems. From there, account takeover leads quickly to identity theft, fraudulent transactions, and, in business contexts, deeper network compromise. The Telegram distribution model also means this data spread rapidly to thousands of threat actors within hours of posting, multiplying the number of people actively using it against real accounts.
How ULP Stealer Log Combolists Are Built and Distributed
ULP stands for URL:Login:Password, and it describes the three-column structure these files use. The underlying data typically comes from infostealer malware, malicious software installed on a victim's computer that silently copies saved browser passwords and sends them to the attacker's server. Attackers then compile thousands of individual stealer logs into massive combined files, clean and sort the data, and post it to Telegram channels or dark web forums as a credential package. Channels like CrakolCloud operate as ongoing services, regularly publishing new batches to maintain their subscriber base. The January 2025 release of 18 million lines from this channel is one entry in a continuing series of credential dumps targeting everyday users across every category of online service.
Check If Your Email Appears in This Leak
With 4.6 million unique email addresses exposed in this single collection, the odds that someone you know is affected are significant. HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including ULP combolists, stealer logs, and dark web credential dumps like CrakolCloud. Visit HEROIC.com to run a free scan, see which of your accounts have been compromised, and get clear guidance on what to change before attackers use your data against you.
Breach Breakdown
4,603,623 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds