Inside UHQ Shopping Base Logs: 587,796 Passwords Harvested
HEROIC traced a stealer log labeled 616K Mix Private UHQ Shopping Base that appeared on Telegram in December 2022. The "UHQ" designation stands for "ultra-high quality," indicating these 587,796 records have been curated and verified by the threat actor for higher success rates. Each entry pairs an email address with a plaintext password and a shopping platform URL, creating a premium-grade attack dataset.
Plaintext Credentials in a Curated Dataset
Not only are these passwords stored in plaintext, but the dataset itself has been filtered for quality. This means the credentials are more likely to be current and functional, making them significantly more dangerous than raw, unfiltered dumps. Attackers can expect a higher hit rate when testing these logins against active shopping accounts.
What Was Exposed
- Email addresses linked to shopping and e-commerce accounts
- Plaintext passwords pre-verified for higher exploitation success
- URLs of specific shopping platforms revealing the targeted services
Shopping Account Compromise and Financial Fraud
When attackers access shopping accounts, they gain entry to stored credit cards, shipping addresses, order histories, and loyalty points. Credential stuffing with these curated credentials can yield rapid unauthorized purchases, gift card fraud, and personal data theft. With 587,796 pre-filtered entries, the potential for financial damage across thousands of victims is substantial.
Anatomy of a Stealer Log: From Browser to Black Market
Infostealer malware silently extracts saved credentials from web browsers, capturing usernames, passwords, cookies, and autofill data from every site the victim has visited. The raw output is then processed by threat actors who sort, categorize, and label the data by target type. Shopping-focused sets like this one command attention because of their direct path to financial exploitation. The finished product is distributed through Telegram and dark web forums.
Check If Your Credentials Were Exposed
If you shop online, your credentials may be part of this curated dataset. HEROIC's breach scanner indexes more than 400 billion compromised records, giving you the ability to check whether your email or password has been leaked. Run a scan today, and if your data appears, immediately change your passwords and remove stored payment methods from any affected shopping accounts.
Breach Breakdown
587,796 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds