Breach Intelligence Report 30 Oct 2024

What farmagol’s LeakBase 50M ULP Part 2 Lets Attackers Do to 9.3M Accounts

HEROIC
HEROIC Threat Intelligence Team
Email Address Homepage Url Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 9,321,844
Source Type Database
Origin Darkweb
Password Type Plaintext

HEROIC analysts identified the LeakBase 50M ULP part 2 by farmagol dataset on July 7, 2024, when it surfaced on an underground forum as a 3.82 GB file titled "50M Lines Url:log:pass." The post carried the same "Good Luck" signature as Part 1, confirming this as a continuation of the same threat actor's release campaign. Of the claimed 50 million total lines, 9,321,844 records were unique, each containing an email address, a homepage URL, and a plaintext password. Part 1 of this series is documented in LeakBase 50M ULP by farmagol.

Why This Is Dangerous

With 9.3 million unique plaintext credential pairs, attackers using this dataset can immediately attempt to access accounts across every platform listed in the URL fields. No password cracking is required. The format of each record tells the attacker which service to target, what email address to use, and what password to enter. Combined with Part 1's 7.4 million records, the farmagol series provides attackers with over 16 million ready-to-use credential sets from a single actor's releases alone.

What Was Exposed

  • Email Address
  • HomePage URL
  • Plaintext Password

Why This Matters

Credential stuffing attacks powered by this dataset can drive account takeover, financial fraud, and identity theft at scale. Attackers test these credentials across banking portals, e-commerce platforms, and email services. Successful logins yield access to saved payment methods, private communications, and secondary accounts linked through shared email addresses. Victims face cascading compromise across multiple services when the same password was reused. The scale of Part 2 alone is sufficient to support sustained automated attack campaigns.

How Database Breaches Work

Stealer log releases like this one originate from infostealer malware infections on end-user devices. The malware captures credentials at the point of entry, recording the site URL alongside the email and password in a URL:login:password format. Operators aggregate logs collected from many infected machines, deduplicate the records, and publish the results in bulk files on underground forums. The URL:log:pass format is a standard packaging convention that makes the data immediately usable for automated credential stuffing tools.

Check If You Are Affected

HEROIC's free identity scanner checks your email address and credentials against more than 400 billion exposed records, including both parts of the farmagol 50M ULP series. Run a scan now to find out whether your credentials appear in this dataset and take immediate action to change any exposed passwords across all platforms where they were used.

Related Parts of This Breach

Breach Breakdown

Domain N/A
Leaked Data Email Address, HomePage URL, Plaintext Password
Password Types Plaintext
Date Leaked 30 Oct 2024
Check in 5 seconds

9,321,844 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,282 scanned today
Breach Rank #356 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $67.5M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance