Dark Web Intel: Xavier Group Stealer Log Exposes 150,908 Logins
Dark web intel gathered by HEROIC threat researchers points to a fresh stealer log making the rounds: Xavier_Ulp - 274000 Xavier_Group, a file holding 150,908 exposed records uploaded to a Telegram channel in late February 2026.
Why This Is Dangerous
Intelligence gathered from dark web channels shows that logs like this one move fast once they are posted, getting copied into other channels and combined with unrelated leaks within days. That speed means the window to act before your credentials get widely distributed is small.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each record
- 150,908 records exposed
Why This Matters
Dark web monitoring exists precisely because leaks like Xavier_Ulp - 274000 Xavier_Group happen quietly, with no press coverage and no official notification to victims. Without active intelligence gathering, most people would never recieve any signal that their credentials were part of a leak like this untill it was far too late, and by then the damage has often already occured.
How Stealer Logs Work
Infostealer malware infects a device, harvests stored browser credentials, and ships the stolen data back to whoever is running the campaign. From there it becomes a log file, gets a name like this one, and enters circulation on the same underground channels that dark web intelligence teams monitor around the clock.
Check If You Are Affected
You do not need your own dark web monitoring team to find out if you were affected. HEROIC's free breach scanner searches more than 400 billion leaked records pulled from sources across the dark web, so you can check Xavier_Ulp - 274000 Xavier_Group and thousands of other leaks in one place.
Breach Breakdown
150,908 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds