Breach Intelligence Report 17 Dec 2024

The LeakBase 11Kk ULP Part 2 Data Quietly Appeared on Dark Web Forums in December

HEROIC
HEROIC Threat Intelligence Team
Email Address Homepage Url Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,142,020
Source Type Database
Origin Darkweb
Password Type Plaintext

On December 7, 2024, the second installment of a stealer log series posted by threat actor firegoon surfaced on underground forums under the LeakBase banner. This second package -- labeled 11Kk ULP (part 2) -- contained approximately 11 million lines and exposed 2,142,020 unique email addresses, each paired with a plaintext password and the homepage URL of the site where the credential was harvested. The first part of this series, LeakBase 11Kk ULP by firegoon, preceded this release as part of a multi-stage credential distribution campaign. The second drop arrived with little announcement -- the kind of quiet addition to dark web forums that rarely draws headlines but leaves millions of accounts immediately at risk.


Why the LeakBase 11Kk ULP Part 2 Dataset Is a Serious Threat

The ULP format -- URL, Login, Password -- is the most directly actionable type of credential dataset available on dark web markets. Unlike raw email lists or hashed password dumps, this dataset hands attackers exactly what they need: the username, the password in plain text, and the specific website to use them on. With 2.1 million such triplets available, automated account takeover tools can begin testing credentials against live services immediately after download, with no additional preparation required.


What Was Exposed in the LeakBase 11Kk ULP Part 2 Breach

  • Email Addresses -- 2,142,020 unique accounts identified as active credential targets
  • Plaintext Passwords -- unencrypted passwords extracted directly from victims' browsers and apps, ready to use without cracking
  • HomePage URLs -- the exact websites where each credential was harvested, mapping every victim to their compromised service

Why This Matters: Credential Stuffing, Account Takeover, and Fraud

When complete credential sets with plaintext passwords circulate on dark web forums, the downstream effects are immediate and compounding:

  • Credential stuffing -- automated tools test each email-password pair across banking, shopping, and email platforms simultaneously, capitalizing on password reuse
  • Account takeover (ATO) -- attackers lock victims out by immediately updating recovery contacts, enabling prolonged access
  • Identity theft -- email account access unlocks password reset flows across financial institutions, government portals, and healthcare platforms
  • Financial fraud -- direct access to e-commerce or banking credentials enables unauthorized purchases and fund transfers within minutes
  • Cascading reuse attacks -- the URL field tells attackers which other sites to target with the same credentials, extending a single stolen password across multiple services

How Multi-Part Stealer Log Releases Work

The "part 2" label signals a deliberate multi-stage release strategy common among stealer log distributors. Here is why actors like firegoon package and release logs in installments:

  1. Malware harvest -- Infostealer malware running on infected devices continuously collects credentials over days or weeks, generating large log archives
  2. Batch processing -- Actors sort and deduplicate logs, dividing them into manageable packages for staged forum releases
  3. Reputation building -- Releasing logs in multiple parts sustains forum visibility and builds the actor's reputation as a reliable data supplier
  4. Timed distribution -- Sequential releases create ongoing demand, with forum members returning to download each new installment
  5. Buyer exploitation -- Each batch is purchased or downloaded by credential stuffing operators who immediately deploy the data against live services

Check If You Are Affected

The HEROIC Identity Scanner searches more than 400 billion exposed records -- including both parts of the firegoon LeakBase 11Kk ULP series -- to determine instantly whether your email address or passwords have been compromised. If your credentials appear in this dataset, you will know immediately.

Scan your email at HEROIC.com -- free and instant, covering over 400 billion breach records.


Related Parts of This Breach Series

This dataset is the second installment in a two-part stealer log release by threat actor firegoon on LeakBase. The first part is also documented:

Breach Breakdown

Domain N/A
Leaked Data Email Address, HomePage URL, Plaintext Password
Password Types Plaintext
Date Leaked 17 Dec 2024
Check in 5 seconds

2,142,020 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,580 scanned today
Breach Rank #N/A by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $15.5M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance