The LeakBase 153Kk ULP 2023 by Chucky Dataset Quietly Appeared on a Hacking Forum Last Week
On November 8, 2024, a dataset named "153Kk ULP 2023 by Chucky" was posted to a well-known hacking forum. It did not generate news coverage. It did not trigger public alerts. It simply appeared -- carrying approximately 154 million records, of which 21.7 million were unique email and plaintext password pairs. That combination is exactly what credential-stuffing operations run on, and it means the accounts attached to those emails were immediately at risk across every platform where those passwords were reused.
This is one of many credential dumps operating under the LeakBase umbrella on underground forums. Related datasets from the same ecosystem include LeakBase RLREBORN 60M ULP by FATHER121 and LeakBase Beast 60M ULP by 1212123 -- each a separate stealer log collection aggregated and posted by different threat actors on the same forum.
Why This Is Dangerous
Plaintext passwords require no cracking. An attacker who obtains this dataset can immediately attempt logins across banking, email, social media, and corporate portals. At 21.7 million unique accounts, even a 1% success rate across credential-stuffing runs translates to over 200,000 compromised accounts. Stealer log collections like this one are bought, traded, and repackaged repeatedly -- exposure does not end when the original post is taken down.
What Was Exposed
- Email addresses (21,670,483 unique records)
- Plaintext passwords
- Homepage URLs (the site the credential was harvested from)
Why This Matters
Stealer log data like this powers some of the most prolific attack categories in cybersecurity:
- Credential stuffing: Automated tools test these email/password pairs across thousands of sites simultaneously, exploiting password reuse.
- Account takeover: Successful logins give attackers access to email inboxes, cloud storage, financial accounts, and corporate systems.
- Identity theft: Email access alone is often enough to reset passwords on banking and government services, enabling full identity compromise.
- Fraud: Hijacked accounts are used for fraudulent purchases, money transfers, and resale on dark web markets.
How Stealer Logs Work
Stealer logs are produced by infostealer malware -- malicious software that infects a victim's device and silently harvests saved passwords, browser sessions, and autofill data. The malware collects credentials from every site the user has logged into on that device, then transmits them to a command-and-control server. These credentials are aggregated into large collections, formatted as URL-login-password (ULP) lists, and sold or posted on hacking forums. "153Kk" refers to approximately 153,000 credential lines; the full dump contained roughly 154 million raw records before deduplication.
Check If You Are Affected
If your email address appears in this dataset, your password for at least one site has been compromised and is available in plaintext. HEROIC's breach database covers over 400 billion exposed records. Search now to find out if your credentials are in this or any other known breach.
Search HEROIC's 400B+ breach database now
Related Parts of This Breach
The LeakBase forum hosts multiple ULP stealer log collections. Other datasets from this same ecosystem:
Breach Breakdown
21,670,483 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds