The LeakBase 11Kk ULP Part 2 Data Quietly Appeared on Dark Web Forums in December
On December 7, 2024, the second installment of a stealer log series posted by threat actor firegoon surfaced on underground forums under the LeakBase banner. This second package -- labeled 11Kk ULP (part 2) -- contained approximately 11 million lines and exposed 2,142,020 unique email addresses, each paired with a plaintext password and the homepage URL of the site where the credential was harvested. The first part of this series, LeakBase 11Kk ULP by firegoon, preceded this release as part of a multi-stage credential distribution campaign. The second drop arrived with little announcement -- the kind of quiet addition to dark web forums that rarely draws headlines but leaves millions of accounts immediately at risk.
Why the LeakBase 11Kk ULP Part 2 Dataset Is a Serious Threat
The ULP format -- URL, Login, Password -- is the most directly actionable type of credential dataset available on dark web markets. Unlike raw email lists or hashed password dumps, this dataset hands attackers exactly what they need: the username, the password in plain text, and the specific website to use them on. With 2.1 million such triplets available, automated account takeover tools can begin testing credentials against live services immediately after download, with no additional preparation required.
What Was Exposed in the LeakBase 11Kk ULP Part 2 Breach
- Email Addresses -- 2,142,020 unique accounts identified as active credential targets
- Plaintext Passwords -- unencrypted passwords extracted directly from victims' browsers and apps, ready to use without cracking
- HomePage URLs -- the exact websites where each credential was harvested, mapping every victim to their compromised service
Why This Matters: Credential Stuffing, Account Takeover, and Fraud
When complete credential sets with plaintext passwords circulate on dark web forums, the downstream effects are immediate and compounding:
- Credential stuffing -- automated tools test each email-password pair across banking, shopping, and email platforms simultaneously, capitalizing on password reuse
- Account takeover (ATO) -- attackers lock victims out by immediately updating recovery contacts, enabling prolonged access
- Identity theft -- email account access unlocks password reset flows across financial institutions, government portals, and healthcare platforms
- Financial fraud -- direct access to e-commerce or banking credentials enables unauthorized purchases and fund transfers within minutes
- Cascading reuse attacks -- the URL field tells attackers which other sites to target with the same credentials, extending a single stolen password across multiple services
How Multi-Part Stealer Log Releases Work
The "part 2" label signals a deliberate multi-stage release strategy common among stealer log distributors. Here is why actors like firegoon package and release logs in installments:
- Malware harvest -- Infostealer malware running on infected devices continuously collects credentials over days or weeks, generating large log archives
- Batch processing -- Actors sort and deduplicate logs, dividing them into manageable packages for staged forum releases
- Reputation building -- Releasing logs in multiple parts sustains forum visibility and builds the actor's reputation as a reliable data supplier
- Timed distribution -- Sequential releases create ongoing demand, with forum members returning to download each new installment
- Buyer exploitation -- Each batch is purchased or downloaded by credential stuffing operators who immediately deploy the data against live services
Check If You Are Affected
The HEROIC Identity Scanner searches more than 400 billion exposed records -- including both parts of the firegoon LeakBase 11Kk ULP series -- to determine instantly whether your email address or passwords have been compromised. If your credentials appear in this dataset, you will know immediately.
Scan your email at HEROIC.com -- free and instant, covering over 400 billion breach records.
Related Parts of This Breach Series
This dataset is the second installment in a two-part stealer log release by threat actor firegoon on LeakBase. The first part is also documented:
- LeakBase 11Kk ULP by firegoon -- Part 1 of this credential dump series
Breach Breakdown
2,142,020 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds