Breach Intelligence Report 14 Jul 2026

How Malware Led to 90K Stolen Logins in the UHQ MIX 2 Dump

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs UHQ MIX 2 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 90,285
Source Type Stealer log
Origin United States
Password Type plaintext

In April 2023, a stealer log compilation labeled UHQ MIX 2 was shared on a public Telegram channel. HEROIC threat intelligence analysts verified that the dataset contained 90,285 records, each tracing a path from an infected device to a compromised account. Every record paired an email address with a plaintext password and the URL where that credential was captured, providing a detailed map of how infostealer malware systematically harvested login data from thousands of victims.


Why Plaintext Credentials Offer Attackers a Direct Path In

None of the 90,285 passwords in this dump were protected by hashing or encryption. They were captured and stored in their original readable form, exactly as each victim entered them. This eliminates the computational work that normally stands between an attacker and a working login. There are no hashes to crack, no salts to account for, and no encryption keys to obtain.

The practical consequence is speed. An attacker who obtains this file can begin testing credentials against live services immediately. Automated tools can process the entire dataset within hours, attempting logins across email providers, banking platforms, social media networks, and enterprise applications. Every successful match grants direct access to the victim's account and everything it contains.


What Was Exposed in the UHQ MIX 2 Dump

  • Email Addresses — Full email addresses harvested from browser autofill and login forms on compromised machines, usable as both account identifiers and targets for follow-up phishing attacks.
  • Plaintext Passwords — Passwords captured in cleartext by malware as victims logged into websites, stored without any transformation and ready for direct exploitation.
  • URLs — The specific login pages and web services where each credential was entered, giving attackers an exact blueprint of which platforms each victim actively used.

Why 90K Credential Pairs Trigger Widespread Account Compromise

Each record in the UHQ MIX 2 dump represents a confirmed, working credential at the time of capture. Even accounting for password changes that some users may have made since April 2023, a significant portion of these credentials remain valid. Users who have not changed their passwords since the leak remain fully exposed.

The damage multiplies through password reuse. When an attacker discovers that one email-password pair works on a particular website, they immediately test the same combination on other platforms. Industry data shows that credential stuffing attacks achieve success rates between 0.1% and 2%, meaning this 90,285-record dataset could yield hundreds or thousands of additional compromised accounts beyond those explicitly listed in the dump.

Financial accounts are particularly vulnerable. Once an attacker establishes control over an email inbox through a reused password, they can initiate password resets on banking and payment platforms, intercept verification codes, and drain accounts before the victim becomes aware of the intrusion.


How Stealer Logs Trace the Journey from Infection to Exposure

The story behind each record in the UHQ MIX 2 dump begins with a malware infection. Infostealer programs like RedLine, Lumma, and Mystic Stealer reach victims through a variety of channels: pirated software bundles, fake browser updates, malicious advertisements, and phishing emails with weaponized attachments. The moment the malware executes, it begins extracting data from the device.

Browser credential stores are the primary target. Every username and password saved in Chrome, Firefox, Edge, or other browsers is copied and packaged. The malware also captures session cookies that could allow attackers to bypass login screens entirely, along with autofill data including names, addresses, and payment card numbers. All of this information is transmitted to a remote server controlled by the attacker.

The collected data is then organized into structured log files, one per victim device. Operators compile these individual logs into larger collections, the combo lists that circulate through underground channels. The UHQ MIX 2 dump represents one such compilation, aggregating data from thousands of individual infections into a single package that was distributed freely on Telegram.


Check If Your Credentials Were Harvested

Infostealer infections often go undetected, which means your credentials could be circulating in dumps like UHQ MIX 2 without your knowledge. HEROIC provides a free breach scanner that cross-references your email address and passwords against more than 400 billion records from known breaches, stealer logs, and dark web data sources.

If any of your credentials are found, take these steps immediately: change the exposed password and any similar passwords used on other services, switch to a password manager that generates unique credentials for every account, enable multi-factor authentication on all platforms that offer it, and run a full malware scan on every device you use to ensure no infostealer is still harvesting your data.

Breach Breakdown

Domain UHQ MIX 2 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

90,285 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,261 scanned today
Breach Rank #N/A by affected users
Impact Score
4
sensitivity + scale + recency
Est. Financial Impact $653.3K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance