One Dark Web Listing. The HUNTERULP Private Archive Had 10,572,371 Records.
HEROIC analysts identified a massive stealer log posted to Telegram in March 2026 under the name "HUNTERULP PRIVATE NEW DATABASE." The file contains 10,572,371 records including email addresses, plaintext passwords, and URLs harvested from infected devices. The label "Private" in the file name suggests this dataset was originally circulated in closed underground communities before becoming more widely available, meaning it may have been actively used by criminal groups for weeks before HEROIC analysts found it.
Why a 10 Million Record Private Stealer Archive Is One of the Most Serious Threats We Track
Files of this scale represent months of coordinated malware activity across thousands of infected devices. A private archive label indicates the data was curated and shared within a restricted criminal network before public distribution. That means organized cybercrime groups had first access to these 10 million credentials, and those groups have the tools and resources to carry out large-scale credential stuffing campaigns, identity fraud, and account takeover attacks. The sheer volume of comprimised accounts makes this one of the more consequential stealer log datasets in our database.
What Was Exposed in the HUNTERULP Private Archive
- Email addresses from victims across multiple countries and providers
- Plaintext passwords captured directly from infected devices before encryption
- URLs identifying the websites and services targeted by the underlying malware campaigns
Why This Archive Creates Ongoing Risk for Identity Theft and Financial Fraud
With over 10 million credential pairs, this dataset will be used in attacks for months or even years after its initial release. Criminals run automated tools that test these credentials across hundreds of websites simultaneously. Banking platforms, retail accounts, email providers, and social media are all targeted. The risk does not end when the file stops circulating. Once credentials are in underground markets, they get repackaged into new combolists and recirculated indefinately. Anyone whose data is in this archive faces ongoing risk until they change their passwords and secure their accounts.
How the HUNTERULP ULP Format Makes This Archive Immediately Usable
ULP stands for URL, Login, and Password. This format is preferred by cybercriminals because it maps each credential directly to the site or service it belongs to, making it straightforward to run targeted attacks against specific platforms. Rather than randomly trying passwords across many sites, attackers can go directly to a specific banking or email platform and try only the credentials that were captured there. This precision is what makes ULP-format stealer logs like this one particularly dangerous compared to generic combolists.
Check If Your Credentials Are in the HUNTERULP Archive
HEROIC's free breach scanner indexes more than 400 billion records, including large-scale archives like the HUNTERULP Private database. If your email address appeared in this file, you will see it in our results immediately along with the data that was exposed. Run a free scan at HEROIC now. With 10 million records in this single archive alone, the chance that your credentials were recieved by this dataset is real and worth checking.
Breach Breakdown
10,572,371 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds