The LeakBase 20M ULP Means Someone Could Log Into Your Accounts Right Now
HEROIC analysts discovered the LeakBase [20M] ULP by savbal stealer log on July 29, 2024, circulating on the hacking forum LeakBase. The dataset contains 2,333,712 unique records drawn from an estimated 20 million total entries, with each record pairing an email address with a plaintext password and an associated homepage URL. A related credential dump from the same platform also appeared around this time: LeakBase Private 26M ULP by selinatest.
Why This Is Dangerous
Plaintext passwords require no cracking. An attacker who downloads this log can immediately attempt to sign in to the email accounts listed, reset passwords on banking, shopping, and social media platforms, and move laterally across any service where the victim reused the same password. Homepage URLs in the dataset tell attackers exactly which services to target first. The result is a rapid, automated account takeover campaign that can drain financial accounts, harvest personal data, and lock victims out of their own inboxes within minutes of the log being deployed.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
Credential stuffing attacks powered by logs like this one succeed because most people reuse passwords across multiple accounts. Once an attacker confirms a working username and password pair against one service, automated tools test those same credentials against hundreds of other platforms simultaneously. The exposure of plaintext passwords dramatically accelerates this process, making account takeover, identity theft, and financial fraud immediate threats for every person in this dataset. Victims may not realize their accounts have been accessed until significant damage has already been done.
How a Stealer Log Breach Works
Stealer logs are collections of credentials harvested by information-stealing malware installed on victims' computers. The malware, often delivered through phishing emails, malicious software downloads, or compromised websites, silently records login credentials as users type them into their browsers. It also captures saved passwords from browser credential stores and session cookies. The collected data is packaged into logs and sold or shared on underground forums. The URL:Login:Password (ULP) format used in this dump is a standard stealer log structure that organizes credentials by the website they belong to, making them immediately usable for targeted account takeover.
Check If You Are Affected
If your email address and password appear in this log, attackers may already be attempting to access your accounts. Use the HEROIC free identity scanner to check your email address against our database of over 400 billion exposed records and find out whether your credentials were included in this dump or any other known breach.
Related Parts of This Breach
- LeakBase Private 26M ULP by selinatest - 2,250,547 unique records exposed on LeakBase on July 28, 2024
Breach Breakdown
2,333,712 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds