Inside UserPass 46k: How a Stealer Harvested 46,081 Credentials
HEROIC analysts tracked a stealer log dataset shared on Telegram in December 2022 containing 46,081 records of username and password pairs. The file, named UserPass_46k, exposes email addresses, plaintext passwords, and URLs gathered by information-stealing malware from tens of thousands of compromised devices. The dataset's naming convention signals that it was purpose-built as a consolidated credential resource for use in automated account takeover attacks.
Inside UserPass 46k: How Stealer Malware Assembled 46,081 Credential Records
Datasets explicitly named after their contents, like UserPass_46k, are typically assembled by combining outputs from multiple stealer malware campaigns. The email addresses, plaintext passwords, and URLs in this file were gathered from infected devices across many different sites and services, giving attackers a diverse pool of credentials to test across platforms. The structured format makes the data immediately usable in automated credential stuffing tools.
What the UserPass 46k Leak Exposed
- Email Addresses
- Plaintext Passwords
- URLs (sites where credentials were captured by malware)
How 46,000 Stolen Credentials Enable Large-Scale Account Takeover Operations
With 46,081 records, this dataset is large enough to run systematic credential stuffing campaigns against multiple platforms simultaneously. Attackers use automated tools that test each email and password pair against banking portals, social media, streaming services, and email providers in rapid succession. Victims whose passwords appear in plaintext here face account takeover risk on any service where they reused that password.
How Stealer Log Breaches Work
Stealer logs are built by information-stealing malware that silently captures login credentials from browsers as users interact with websites. Each captured credential includes the email or username, the password in cleartext, and the URL of the site. Malware operators collect these logs from large networks of infected devices, combine them into bulk datasets, and distribute them through Telegram. The resulting files provide ready-made inputs for automated account takeover tools.
Check If Your Data Was Exposed
HEROIC's free breach scanner covers more than 400 billion exposed records, including the UserPass 46k dataset and thousands of similar stealer log files. Search your email to find out whether your credentials are included, and use a password manager to generate unique passwords for each of your accounts to reduce your exposure to credential stuffing attacks.
Breach Breakdown
46,081 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds