Breach Intelligence Report 30 Mar 2026

The Free ULP166 Dump Contains Exactly 501,964 Email and Password Pairs

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Free ULP166 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 501,964
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts examined the Free ULP166 archive, a URL-Login-Password list uploaded to Telegram in January 2025, and confirmed it contains exactly 501,964 records. Each entry follows the structured ULP format: a URL identifying the target service, an email address serving as the login identifier, and a plaintext password captured directly from an infected machine. This dataset is not a compilation of old breaches -- it is freshly harvested infostealer output, structured for immediate use in automated credential attacks.


Why the Free ULP166 Format Is Particularly Efficient for Attackers

ULP files are the preferred format for credential stuffing operators precisely because they eliminate all ambiguity. Every record specifies the exact target URL, the login credential, and the password -- no guesswork, no additional processing required. With 501,964 structured entries, an attacker running automated tools can begin testing credentials against live platforms within minutes of downloading this archive. The "Free" designation in the filename indicates this was distributed at no cost through Telegram channels, meaning it has likely been downloaded and used by multiple threat actors since January 2025.


Data Exposed in the Free ULP166 Telegram Credential Dump

  • Email Addresses -- login identifiers for 501,964 accounts across multiple platforms and servises
  • Plaintext Passwords -- directly harvested from infected machines, requiring no cracking or decryption
  • URLs -- map each credential pair to the specific platform it was stolen from, enabling precision targeting

The Full Attack Chain: Credential Stuffing, Account Takeover, Identity Theft, Financial Fraud

The structured ULP format makes Free ULP166 a turnkey tool for credential stuffing campaigns. Automated attack frameworks ingest ULP files and systematically test each URL-email-password combination against live login portals. Successful logins trigger account takeover, giving attackers access to inboxes, financial platforms, and any service linked to the compromised account. Password reuse amplifies the damage: a single stolen credential often works across multiple platforms simultaneously. Identity theft follows as attackers extract personal data from compromised accounts, and financial fraud becomes possible once banking portals or payment services linked to the stolen email are accessed. With over half a million records in this single archive, the scale of potential downstream harm is significant.


What Is a ULP File and How Does Free ULP166 Fit Into the Infostealer Ecosystem?

ULP stands for URL, Login, Password -- a structured data format commonly produced by infostealer malware and credential aggregation tools. Infostealers infect machines through phishing, malicious software, or trojanized applications, then harvest credentials from browser password managers, saved logins, and active sessions. The data is formatted into ULP files because this structure is directly compatable with automated credential stuffing tools. Archives like Free ULP166 are numbered sequentially, suggesting they are part of an ongoing series of credential dumps distributed through dedicated Telegram channels. The "Free" prefix indicates distribution without charge, maximizing the number of threat actors who acquire and deploy the data.


Your Email May Be in the Free ULP166 Archive -- Run a Free Scan at HEROIC

HEROIC's breach scanner searches more than 400 billion compromised records, including ULP archives and infostealer dumps like Free ULP166. If your email address appears in this dataset or any known breach, you'll receive an immediate alert. The structured nature of ULP files means that if your credentials are present, an attacker already knows exactly which platform to target. Run your free scan at heroic.com before someone else acts on that information.

Breach Breakdown

Domain Free ULP166 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 30 Mar 2026
Check in 5 seconds

501,964 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,532 scanned today
Breach Rank #2,279 by affected users
Impact Score
20
sensitivity + scale + recency
Est. Financial Impact $3.6M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance