If You Reuse Passwords, the Xentoxx Leak Should Worry You
HEROIC's DarkHive intelligence platform has detected a significant stealer log titled Xentoxx ULP, containing 79,454 compromised records. Uploaded to Telegram in December 2024, this dataset is a URL-Login-Password (ULP) formatted file — a structured stealer log format that pairs each compromised website URL with its corresponding email and password, making it trivially easy for attackers to exploit.
Plaintext Passwords in a Structured Attack Format
The ULP format is particularly dangerous because it organizes credentials in a way that is directly compatible with automated attack tools. Each line contains a URL, login, and plaintext password — no parsing, no decryption, no preparation needed. Attackers can feed this file directly into credential testing software and begin attempting logins across the 79,454 recorded accounts within seconds of downloading the file.
What Was Exposed
- Email Addresses — Login identifiers spanning thousands of different websites
- Plaintext Passwords — Unencrypted credentials in ready-to-exploit format
- URLs — The exact websites where each credential pair was saved
79,454 Reasons to Stop Reusing Passwords
With nearly 80,000 credential pairs in a single file, the statistical likelihood that some of these users reuse passwords is virtually certain. Credential stuffing attacks will test each pair against banking, email, social media, cloud storage, and corporate platforms. If you have ever used the same password on multiple sites, a breach of this size dramatically increases the chance that one of your accounts is directly exposed — and every account sharing that password becomes collateral damage.
What Makes ULP Stealer Logs Different
ULP files are the output of infostealer malware like RedLine, Lumma, Vidar, and Stealc. These malware variants hook into browser processes to extract the saved credentials database, capturing the URL, username, and password for every site the victim has logged into. The data is formatted into URL:Login:Password lines, creating a ready-made attack database. The Xentoxx label likely refers to the threat actor or distribution group responsible for compiling and sharing this particular collection of stolen data.
Check If Your Credentials Were Exposed
HEROIC's free breach scanner searches a database of over 400 billion compromised records. Enter your email address to see if your credentials are part of this Xentoxx ULP dump or any other known breach. With 79,454 records in this single leak, checking your exposure and changing compromised passwords is an essential step to prevent unauthorized account access.
Breach Breakdown
79,454 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds