Breach Intelligence Report 14 Jul 2026

Dragon_ULP 7 Leak Means 2.7M Accounts Are Ready to Steal

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs PRIVATE ULP BY DRAGON_ULP 7 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,739,813
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC threat intelligence analysts identified a large-scale stealer log distribution labeled PRIVATE ULP BY DRAGON_ULP 7 on a Telegram channel in March 2026. The dump contained 2,739,813 records, each combining an email address with a plaintext password and the URL where those credentials were used. With nearly 2.8 million account credentials exposed in ready-to-use form, this leak represents one of the more significant stealer log distributions tracked by HEROIC in recent months.


Why These Plaintext Passwords Are an Open Invitation to Attackers

Every password in the Dragon_ULP 7 dump was stored without any form of encryption or hashing. The credentials appear in their original, human-readable format, exactly as victims typed them into login pages. For an attacker, this is the ideal scenario. There is no computational barrier, no time investment in cracking hashes, and no specialized hardware required. The passwords work the moment they are copied.

At the scale of 2.7 million records, the threat is acute. Automated attack frameworks can ingest this entire dataset and begin testing credentials against major platforms within minutes. Even a fraction of a percent success rate translates to thousands of compromised accounts, each one a potential gateway to financial theft, identity fraud, or corporate espionage.


What Was Exposed in the Dragon_ULP 7 Dump

  • Email Addresses — Nearly 2.8 million email addresses extracted from infected endpoints, each serving as a login identifier and a direct channel through which attackers can deliver targeted phishing messages or password reset requests.
  • Plaintext Passwords — Fully readable passwords siphoned from browser credential stores and login sessions on compromised devices, requiring no processing before they can be weaponized against victim accounts.
  • URLs — The web addresses where each credential pair was captured, revealing the full scope of services each victim accessed and enabling attackers to prioritize high-value targets like banking, email, and enterprise platforms.

Why 2.7 Million Exposed Credentials Pose a Systemic Risk

A dataset of this magnitude does not just threaten individual users. It threatens entire organizations and platforms. When millions of credentials circulate freely, the volume of credential stuffing attacks against any given service spikes dramatically. Platforms that lack robust rate limiting or multi-factor authentication enforcement become easy prey.

For individuals, the risk is compounded by password reuse. Each person who used the same password across multiple services now has every one of those accounts exposed. An attacker who finds a working credential on a low-security site will immediately attempt it on email services, cloud platforms, financial institutions, and corporate networks. The 2,739,813 records in this dump could represent tens of millions of vulnerable accounts when reuse is factored in.

Corporate security teams face an additional concern. If any employee's personal device was infected by the infostealer that produced these logs, corporate credentials saved in the same browser are likely included in the dump alongside personal ones.


How Stealer Logs Enable Industrial-Scale Credential Harvesting

The Dragon_ULP series of stealer log compilations points to an organized operation. Infostealer malware variants like Lumma, Vidar, and RisePro infect devices through phishing campaigns, malicious advertisements, and compromised software distribution channels. Each infected machine yields a log file containing every credential, cookie, and autofill entry stored in the victim's browsers.

Operators behind these campaigns collect thousands of individual log files daily. They aggregate the data into large compilations, sometimes organized by geography, service type, or perceived value. The DRAGON_ULP label suggests a recurring distributor who periodically releases new batches, with the number 7 indicating this is at least the seventh installment in the series.

Distribution through Telegram provides the operator with reach and anonymity. Channels can attract thousands of subscribers who receive each new dump automatically. The data spreads rapidly, with multiple threat actors downloading and using the same credentials simultaneously, creating a race condition where the first attacker to test a valid credential claims the account.


Check If Your Credentials Are in the Dragon_ULP 7 Dump

Given the scale of this leak, verifying your exposure is essential. HEROIC offers a free breach scanner that searches more than 400 billion records from known breaches, stealer logs, and dark web marketplaces to determine whether your email address or passwords have been compromised.

If your credentials appear in the Dragon_ULP 7 dump or any related dataset, respond immediately. Change compromised passwords across every service where they were used, deploy a password manager to eliminate reuse, activate multi-factor authentication on all accounts, and run comprehensive anti-malware scans on every device to detect and remove any active infostealers.

Breach Breakdown

Domain PRIVATE ULP BY DRAGON_ULP 7 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

2,739,813 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,692 scanned today
Breach Rank #N/A by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $19.8M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance