What farmagol’s LeakBase 50M ULP Part 2 Lets Attackers Do to 9.3M Accounts
HEROIC analysts identified the LeakBase 50M ULP part 2 by farmagol dataset on July 7, 2024, when it surfaced on an underground forum as a 3.82 GB file titled "50M Lines Url:log:pass." The post carried the same "Good Luck" signature as Part 1, confirming this as a continuation of the same threat actor's release campaign. Of the claimed 50 million total lines, 9,321,844 records were unique, each containing an email address, a homepage URL, and a plaintext password. Part 1 of this series is documented in LeakBase 50M ULP by farmagol.
Why This Is Dangerous
With 9.3 million unique plaintext credential pairs, attackers using this dataset can immediately attempt to access accounts across every platform listed in the URL fields. No password cracking is required. The format of each record tells the attacker which service to target, what email address to use, and what password to enter. Combined with Part 1's 7.4 million records, the farmagol series provides attackers with over 16 million ready-to-use credential sets from a single actor's releases alone.
What Was Exposed
- Email Address
- HomePage URL
- Plaintext Password
Why This Matters
Credential stuffing attacks powered by this dataset can drive account takeover, financial fraud, and identity theft at scale. Attackers test these credentials across banking portals, e-commerce platforms, and email services. Successful logins yield access to saved payment methods, private communications, and secondary accounts linked through shared email addresses. Victims face cascading compromise across multiple services when the same password was reused. The scale of Part 2 alone is sufficient to support sustained automated attack campaigns.
How Database Breaches Work
Stealer log releases like this one originate from infostealer malware infections on end-user devices. The malware captures credentials at the point of entry, recording the site URL alongside the email and password in a URL:login:password format. Operators aggregate logs collected from many infected machines, deduplicate the records, and publish the results in bulk files on underground forums. The URL:log:pass format is a standard packaging convention that makes the data immediately usable for automated credential stuffing tools.
Check If You Are Affected
HEROIC's free identity scanner checks your email address and credentials against more than 400 billion exposed records, including both parts of the farmagol 50M ULP series. Run a scan now to find out whether your credentials appear in this dataset and take immediate action to change any exposed passwords across all platforms where they were used.
Related Parts of This Breach
- LeakBase 50M ULP by farmagol — 7,450,011 unique records, leaked July 10, 2024
Breach Breakdown
9,321,844 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds