LeakBase 6.6GB ULP Dump: 916,549 Stolen Credentials Exposed
HEROIC analysts identified a stealer log published to LeakBase on September 4, 2024, attributed to a user identified as "blockchair." The release, titled 6.6Gb Url Log Pass#2, contained approximately 7.3 million total records. From that dataset, 916,549 unique records were confirmed, each consisting of an email address, a homepage URL, and a plaintext password. This is a standalone release with no confirmed series siblings detected at the time of analysis.
The ULP structure of this dataset, meaning each line maps a URL to a login and password, makes it immediately operational for attackers. The 6.6 gigabyte size signals a broad sweep of infected endpoints, with credentials collected from many different websites and services packaged into a single file. The presence of homepage URLs alongside each email and password removes the guesswork for attackers: they know exactly which service each credential belongs to, enabling targeted login attempts rather than broad spraying.
What Was Exposed
- Email Address
- HomePage URL
- Plaintext Password
Why This Matters
Plaintext passwords in combination with email addresses and service URLs represent the most complete and immediately exploitable credential format in existence. Credential stuffing tools can ingest this data directly and begin testing logins at scale across financial platforms, email services, e-commerce sites, and workplace applications. For victims who reuse passwords, a single exposed record can compromise multiple accounts simultaneously. The downstream risk includes unauthorized financial transactions, identity theft, phishing attacks launched from compromised inboxes, and unauthorized access to sensitive business systems.
How Database Breaches Work
Stealer log releases like this one originate from infostealer malware distributed through phishing campaigns, malicious browser extensions, or trojanized software installers. When a device is infected, the malware collects credentials saved in the browser, records the URLs they belong to, and exfiltrates that data silently to attacker servers. The collected records are then compiled into structured ULP logs, which stand for URL, Login, Password, and distributed on underground forums and marketplaces. The LeakBase platform has historically served as a distribution channel for this type of credential data, with files like this one shared publicly or semi-publicly to build reputation or monetize access.
Check If You Are Affected
HEROIC's free breach scanner searches across a database of over 400 billion records to determine whether your email address has appeared in known credential dumps, including stealer log releases from platforms like LeakBase. If your data was included in the LeakBase 6.6GB ULP by blockchair release, you should rotate the affected passwords immediately and enable two-factor authentication on any accounts that used those credentials. Check if your data was exposed for free at HEROIC.
Breach Breakdown
916,549 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds