Our Analysts Found the LeakBase 14Kk ULP by farmagol Circulating on Hacking Forums
Our analysts discovered the LeakBase 14Kk ULP by farmagol dump posted on a prominent hacking forum on December 21, 2024. The file contained approximately 14 million raw records, of which 3.53 million were unique combinations of email addresses, homepage URLs, and plaintext passwords. This is part of an ongoing series of credential dumps published under the farmagol handle, and its appearance follows a pattern of escalating stealer log releases that have collectively exposed tens of millions of credentials. The presence of plaintext passwords makes this dump immediately weaponizable without any additional cracking.
Related dumps from the same actor series:
- LeakBase 5Kk ULP by farmagol
- LeakBase 32Kk ULP by farmagol
- LeakBase 50M ULP by farmagol
- LeakBase 50M ULP Part 2 by farmagol
Why the LeakBase 14Kk ULP Dump Is Dangerous
Most breach dumps contain hashed passwords that require time and computing power to crack. This dump is different. The passwords are stored in plaintext, meaning anyone who downloads the file has immediate, ready-to-use access to 3.53 million account credentials. There is no barrier between the attacker and your account.
What Was Exposed
- Email address
- Homepage URL (the site where the credential was harvested)
- Plaintext password
Why This Matters
Plaintext credentials like these are the primary fuel for credential stuffing attacks, where bots automatically test username and password combinations across hundreds of sites. If you reuse the same password on multiple accounts, a single exposed credential can cascade into a full account takeover across your email, banking, social media, and shopping accounts. These dumps are also used for targeted phishing, identity theft, and fraud, particularly when the homepage URL reveals what service you were using.
How Stealer Logs Work
A stealer log is a collection of credentials harvested by malware installed on victims' computers, typically through phishing emails, malicious downloads, or infected software. The malware silently captures usernames and passwords as victims type them, then sends the data back to the attacker. The attacker compiles thousands or millions of these records into a single file, which is then sold or posted on hacking forums. ULP stands for URL-Login-Password, the standard format for organizing stolen credentials by the website they were stolen from.
Check If You Are Affected
HEROIC monitors more than 400 billion exposed records, including stealer logs like this farmagol series. If your email address and password appeared in any of these dumps, our platform will alert you immediately. Run a free scan at HEROIC.com to see if your credentials are circulating on hacking forums right now.
Related Parts of This Breach Series
The farmagol actor has published multiple credential dumps under the LeakBase label. The following related releases have been documented:
Breach Breakdown
3,530,731 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds