Dark Web Intel: Xavier_Group Stealer Log Leaks 109,889 Logins
HEROIC's dark web monitoring picked up a file called Xavier_Ulp - 366919 Xavier_Group after it was uploaded to Telegram in February 2026. Inside, analysts counted 109,889 exposed records tied to real logins.
Why This Is Dangerous
Smaller stealer logs like this one can actually be more dangerous than the massive ones, because they get less attention and stay under the radar longer. Criminals treat these seperate niche files as fresh, unpicked inventory, wich means the credentials inside are more likely to still work when someone finally tries them.
What Was Exposed
- 109,889 total records
- Email addresses
- Plaintext passwords
- URLs linked to each account
Why This Matters
Because the file was labeled and grouped under a specific name, Xavier_Group, it suggests these logins were pulled from a related batch of infected machines. If you recognize any pattern here, shared devices, a specific software download, or a work network, its definately a signal to check your own credentials right away.
How Stealer Logs Work
Stealer malware infects a machine silently, often bundled with cracked software or fake installers, then digs through the browser for anything saved, passwords, cookies, and autofill entries. Everything gets zipped into a log and shipped off to the attacker's server, then repackaged and posted to places like Telegram for other criminals to grab, exactly what happened here.
Check If You Are Affected
Dark web intel like this is only useful if you act on it. Run a free scan through HEROIC's breach scanner, wich checks your email against more than 400 billion leaked records in seconds.
Breach Breakdown
109,889 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds