HEROIC Analysts Flag ULP LGS 035 Part 22: 365,595 Exposed
HEROIC analysts flagged part 22 of the ULP LGS 035 series this week, a stealer log file exposing 365,595 records that slots neatly between the other numbered parts of the same ongoing leak.
Why This Is Dangerous
Analysts tracking this series note that each new part adds another few hundred thousand working credentials to an already massive collection. Part 22 alone is large enough to power targeted phishing campaigns against a wide range of victims.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs for each captured login
This file holds 365,595 records, each one a seperate email, password, and site combination pulled from infected devices.
Why This Matters
Once attackers recieve a new part of the LGS 035 series, they typically merge it with the parts they already have, building an ever larger list of confirmed working logins. Anyone flagged by this leak should imediately update their passwords, especially on accounts tied to email, banking, or work systems.
How Stealer Logs Work
Part 22 fits the same pattern as the rest of the LGS 035 series, built from stealer malware that harvests saved browser credentials and ships them off to a central collection point. From there, the operators split the haul into numbered files to make distribution across Telegram channels easier to manage.
Check If You Are Affected
HEROIC analysts recommend checking your exposure directly rather than waiting for another part of this series to surface. Our free breach scanner searches more than 400 billion leaked records and will show you instantly if your email appears in part 22 or any other breach.
Breach Breakdown
365,595 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds