Inside the UHQ Streaming and Gaming Logs: 100,000 Passwords Harvested
In April 2023, HEROIC threat intelligence analysts cataloged a stealer log distributed under the name 100K UHQ Combo for Streaming Gaming. The dataset, shared through a Telegram channel, contains exactly 100,000 records of credentials harvested from infected devices. The label "UHQ" (Ultra High Quality) indicates the compiler curated these entries for high-value targets, specifically streaming and gaming platform accounts in the United States.
Each record pairs an email address with a plaintext password and the URL where the credentials were captured. This structured format allows attackers to immediately identify which platform each login belongs to and begin exploitation without any preprocessing or guesswork.
Why Plaintext Passwords Eliminate Every Layer of Defense
The technical significance of plaintext password exposure cannot be understated. In a conventional database breach, passwords are typically stored as cryptographic hashes, often with per-user salts. Reversing these hashes requires brute-force computation or rainbow table lookups, which can take hours, days, or even years depending on the hashing algorithm. None of that applies here.
Every one of the 100,000 passwords in this dump was intercepted in its original, unencrypted form as it was transmitted from the browser to the login server. The infostealer malware that compiled these logs operates at the application layer, hooking into browser processes to capture credentials before any client-side encryption occurs.
From an attacker's technical perspective, these credentials are immediately actionable. They can be loaded directly into credential stuffing frameworks, automated login tools, or manual access attempts with zero transformation required. The time-to-exploitation is measured in seconds, not days.
What Was Exposed in the UHQ Streaming and Gaming Dump
- Email Addresses — Account identifiers for streaming and gaming platforms, many of which also serve as the primary recovery email for linked accounts and payment services.
- Plaintext Passwords — Raw, unencrypted passwords intercepted at the browser level before any transport-layer security could protect them, exactly as the user typed them.
- URLs — The specific login endpoints where credentials were captured, identifying which streaming services, gaming platforms, and associated sites each victim accessed.
Why 100,000 Streaming and Gaming Credentials Have Outsized Value
Streaming and gaming accounts carry significant underground market value. Premium streaming subscriptions can be resold for a fraction of retail price, and gaming accounts often contain in-game currencies, rare items, and linked payment methods worth hundreds or thousands of dollars. The UHQ designation on this dump signals that these are verified, working credentials rather than stale or untested entries.
Credential stuffing attacks against streaming platforms have a notably high success rate because users frequently share passwords between their streaming, gaming, and email accounts. Security researchers have found that entertainment accounts are among the most commonly reused credentials, with users applying the same password to an average of four to five different services.
The 100,000 records in this collection represent a substantial operational dataset for attackers. At underground market rates, compromised streaming accounts sell for two to five dollars each, while gaming accounts with valuable inventories can fetch significantly more. The aggregate commercial value of this dump incentivizes rapid, large-scale exploitation.
How Stealer Logs Extract Credentials at the System Level
The infostealer malware responsible for this dataset operates through several well-documented technical mechanisms. Common variants such as RedLine, Raccoon, and Vidar inject themselves into browser processes to read credential databases stored locally. Chromium-based browsers store passwords in SQLite databases encrypted with DPAPI, which the malware decrypts using the logged-in user's Windows credentials.
Beyond browser password stores, these tools also extract cookies (enabling session hijacking), autofill data, cryptocurrency wallet files, and system fingerprints. The compiled log is exfiltrated to a command-and-control server, then aggregated with logs from thousands of other infected machines. The resulting datasets are sorted, labeled, and distributed through Telegram channels and dark web marketplaces.
The 100K UHQ Streaming Gaming log follows this standard pipeline. The "combo" format pairing URLs, emails, and passwords indicates post-processing by the distributor to strip away non-credential data and organize entries by service category, making the file immediately useful for targeted account takeover operations.
Check If Your Credentials Were Exposed in This Dump
If you use streaming or gaming platforms and have ever saved your password in a browser, there is a real possibility your credentials were captured by infostealer malware and appear in this or a similar dataset. The 100,000 records here are just one slice of a much larger ecosystem of stealer log distribution.
HEROIC has indexed more than 400 billion compromised records, including stealer logs targeting streaming and gaming accounts. Use the free breach scanner to check whether your email address appears in this dataset and take action before attackers do.
If your credentials are found, change passwords immediately on all streaming and gaming platforms. Revoke any active sessions, review linked payment methods for unauthorized charges, and enable two-factor authentication. If you reused the exposed password on other services, change those as well.
Breach Breakdown
100,000 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds