465,246 Plaintext Passwords From LeakBase 40M ULP Hit the Dark Web
HEROIC analysts identified a stealer log posted to LeakBase on July 30, 2024 by threat actor 1212123, catalogued as "40Million Lines Url-Log-Pass 1Cr." The log contained approximately 35.5 million email addresses and exposed 465,246 unique email addresses paired with plaintext passwords and associated HomePage URLs. This release is part of a coordinated multi-part dumping campaign by the same actor, which also includes LeakBase 20M ULP by 1212123, LeakBase 30M ULP by 1212123, LeakBase 70M ULP by 1212123, LeakBase Horizon Clouds 40M ULP by 1212123, LeakBase Horizon Clouds 100M ULP by 1212123, and LeakBase Beast 60M ULP by 1212123.
With passwords exposed in plaintext, attackers face zero friction. Every email-password pair in this dataset can be fed into automated credential stuffing tools immediately, testing logins across banking, webmail, social media, and e-commerce platforms without needing to crack or decode anything. The HomePage URLs bundled with each record tell attackers exactly which sites each victim frequents, enabling them to prioritize attacks against accounts where the impact will be highest.
What Was Exposed
- Email addresses
- Plaintext passwords
- HomePage URLs
Why This Matters
When passwords leak in plaintext, every account where that password is reused becomes immediately vulnerable. Credential stuffing attacks powered by logs like this one are responsible for a significant share of account takeovers globally. Attackers who gain access to an email account can reset passwords on linked services, leading to cascading identity theft, fraudulent transactions, and unauthorized access to employer systems if a personal device or email was used for work logins.
How Stealer Log Leaks Work
Infostealer malware infects a victim's device through phishing lures, trojanized software, or malicious browser extensions. Once active, the malware reads saved credentials directly from browser storage and password managers, then sends the captured data to a remote server controlled by the attacker. These records are compiled into URL-login-password (ULP) formatted text files and posted or sold on hacking forums like LeakBase. The ULP format is specifically structured for easy import into automated attack tools, making the path from stolen credential to account compromise extremely short.
Check If You Are Affected
HEROIC's free breach scanner checks your email address against more than 400 billion exposed records, including stealer log data like this LeakBase 40M ULP dump. Run a free scan now to find out whether your credentials appeared in this or any related breach, and get clear steps to secure your accounts.
Related Parts of This Breach
Breach Breakdown
465,246 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds