Global Users Targeted: UHQ Mix Exposes 246,782 Passwords
HEROIC's dark web monitoring operations identified a large mixed-target stealer log collection labeled UHQ MIX PART 1 0916 being shared on Telegram. Dated February 2023, this dataset contains 246,782 records harvested from infected devices worldwide, exposing email addresses, plaintext passwords, and URLs spanning a wide variety of online services and platforms.
Plaintext Passwords Leave No Room for Defense
Every one of the 246,782 passwords in this collection is stored in plaintext—completely unencrypted and readable without any tools. Unlike breaches where passwords are hashed, giving defenders time to notify users before credentials are cracked, plaintext exposure means all 246,782 accounts are immediately vulnerable. Attackers can begin exploiting them the instant they access the file, with no technical barriers standing in the way.
What Was Exposed
- Email Addresses — accounts from email providers, social platforms, and business services across multiple countries
- Plaintext Passwords — fully readable passwords with zero encryption
- URLs — a diverse range of login pages from banking, retail, social media, and enterprise applications
Mixed-Target Dumps Maximize Credential Stuffing Impact
Unlike dumps that focus on a single service, mixed combolists like UHQ MIX cast a wide net. The 246,782 credential pairs span numerous platforms, giving attackers readymade ammunition for cross-service credential stuffing. Each email-password combination is tested against hundreds of popular services simultaneously. Users who share passwords between their shopping accounts, email, banking, and work platforms face the highest risk—one match can cascade into compromises across their entire digital footprint.
Inside the Infostealer Supply Chain
Mixed stealer log collections like this one are assembled from thousands of individual malware infections. Infostealers such as RedLine, Raccoon, or Lumma infect devices through phishing emails, malvertising, and fake software downloads. Each infection yields a log file containing the victim's saved browser passwords, cookies, and autofill data. Threat actors then aggregate these individual logs into large compilations, sort them by quality and category, and distribute them through Telegram channels and dark web marketplaces.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database indexes over 400 billion records from data breaches, stealer logs, and dark web sources around the world. Use HEROIC's free breach scanner to determine if your email or credentials appear in the UHQ MIX PART 1 0916 dump or any other known leak. If you discover a match, immediately change the affected password, verify that each of your accounts uses a unique password, and activate two-factor authentication on all important services.
Breach Breakdown
246,782 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds