The Dragon_ULP Combolist Leaked 2.4 Million Login Credentials
In June 2026, HEROIC analysts tracked a large combolist labeled "PRIVATE ULP BY DRAGON_ULP" being distributed by a Telegram user. This one is significant in scale: it contains 2,405,684 records, each pairing an email address with a plaintext password and the URL of the site that login was used on. At well over two million entries, it's one of the larger combolists HEROIC has logged from Telegram distribution channels this year.
Why a Combolist This Size Is Dangerous
Scale matters here. A file with 2.4 million working email and password pairs gives attackers enough raw material to run large, automated attacks across dozens of websites at once, rather than targeting one person or one company. Because the passwords are stored in plaintext and each record already lists the exact site it belongs to, criminals can plug this list directly into automated login tools with no extra work required.
What Was Inside the Dragon_ULP Combolist
- Email addresses (used as usernames)
- Plaintext passwords, stored in unencrypted, readable form
- URLs identifying the exact website each login was captured from
Why This Could Unlock More Than One Account
If you reuse a password across more than one site, a single exposed login can act like a master key. Attackers take email and password pairs from lists like this and test them against banking portals, email providers, and social media platforms in a process called credential stuffing. One matching login can lead to a drained account, a hijacked inbox, or a social media profile taken over and used to scam contacts, all from data that was never tied to a single confirmed source in the first place.
How a Combolist This Large Gets Assembled
Combolists like this one aren't the result of a single company being hacked. Instead, criminals pull login data from many older breaches, phishing campaigns, and malware infections, then merge, clean, and organize it into one massive file. Labels like "ULP" (URL, login, password) and "PRIVATE" are used to market the list's quality to buyers on Telegram and dark web forums. Because it draws from so many original sources, a list this size can touch accounts on hundreds, even thousands, of different websites.
Check If Your Email Is Among the 2.4 Million Records
With a combolist this large, there's a real chance your email address is one of the 2,405,684 records involved, and no reliable way to know without checking. HEROIC's free dark web breach scanner checks your email against a database of more than 400 billion leaked records, including combolists like this one, so you can find out fast and change any exposed passwords before they're used against you.
Breach Breakdown
2,405,684 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds