LeakBase 100M ExodusULP: Exactly 18,484,530 Stolen Login Pairs
HEROIC analysts flagged a significant data dump on June 6, 2024, surfacing on a well-trafficked underground forum under the name "LeakBase 100M ExodusULP by exodusproj." The file, described as containing over 108 million lines of raw data, was analyzed and confirmed to hold 18,484,530 unique email addresses, each matched with a plaintext password and in most cases a homepage URL. The name "ExodusULP" follows the naming convention of URL-login-password formatted credential lists, a structure widely used by cybercriminals to organize and weaponize stolen account data. The scale of this dump places it among the larger stealer log compilations seen in 2024.
Why This Is Dangerous
With over 18 million plaintext passwords in a single file, this dump represents an enormous ready-to-use toolkit for attackers. Unlike hashed or encrypted passwords, plaintext passwords require no additional processing. An attacker can immediately begin testing these credentials against banking sites, email providers, and other platforms. The homepage URLs included in each record add useful context, helping criminals understand which services a victim regularly logs into and prioritizing which accounts to target first. This is not a theoretical risk. Dumps of this type are routinely used within days of being posted.
What Was Exposed
The following personal data types were confirmed in this leak:
- Email addresses
- Plaintext passwords
- Homepage URLs
Why This Matters
Credential stuffing is the most immediate threat from a dump like this. Automated tools allow criminals to test millions of username and password combinations across hundreds of websites within a matter of hours. Because a significant portion of people reuse passwords across multiple accounts, a single compromised credential can lead to account takeover on several platforms at once. From there, attackers can drain financial accounts, lock users out by changing passwords, harvest personal information for identity theft, or sell verified working logins to other criminals. The occured damage from a dump this size can ripple across millions of people who recieved no warning that their data was even at risk.
How a Database Breach Works
A database breach happens when attackers gain unauthorized access to the systems that store user account information. This can happen through a variety of methods, including exploiting software vulnerabilities, using stolen administrative credentials, or taking advantage of misconfigured servers that are unintentionally exposed to the internet. Once inside, attackers copy the database and extract all stored records. Depending on how the data was stored, passwords may be plaintext from the start or may have been decrypted after the fact. The stolen data is then typically sold on dark web markets or shared on hacking forums, where others download it and put it to use. Victims often do not find out for months or even years.
Check If You Are Affected
With 18.4 million accounts exposed in the LeakBase 100M ExodusULP dump alone, the chances that someone you know is affected are meaningful. HEROIC's free breach scanner searches more than 400 billion records from known data leaks to tell you in seconds whether your email address has been compromised. If your email appears in this or any other breach, change your passwords immediately, avoid reusing passwords across sites, and enable two-factor authentication on your most important accounts.
Breach Breakdown
18,484,530 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds