The LeakBase 7.9Kk ULP by Firegoon Put 2.6M Stolen Login Pairs Online
HEROIC analysts identified a stealer log released on July 20, 2024, on a prominent underground hacking forum. The log, posted by the threat actor firegoon under the label "7,9Kk ULP," exposed 2,682,689 unique records containing email addresses, plaintext passwords, and homepage URLs. This release is part of a broader series of credential dumps posted by firegoon across multiple LeakBase releases, including LeakBase 10Kk ULP by firegoon, LeakBase 10.5Kk ULP by firegoon, LeakBase 22Kk ULP by firegoon, and LeakBase 8.7M ULP by firegoon.
With 2.6 million plaintext passwords in hand, attackers can immediately attempt credential stuffing across email providers, banking portals, and social media platforms without needing to crack anything. The inclusion of homepage URLs tells attackers exactly which sites each victim was visiting, enabling them to target those specific services first. Users who reuse passwords across multiple accounts face total account takeover from a single matched credential pair.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
Plaintext password leaks require no cracking step, giving any attacker immediate login capability against every reused account. The combination of email address and matching password enables automated credential stuffing at scale across thousands of websites simultaneously. Victims face account takeover on banking, shopping, and personal accounts, and the associated homepage URLs narrow the attack surface to sites the victim is known to use, increasing success rates. Identity theft and downstream fraud become a direct risk for everyone in this dataset.
How Database Breaches Work
Stealer log database breaches like this one originate from infostealer malware that silently infects victims' devices. Once installed, the malware harvests credentials saved in browsers, autofill data, and active sessions. It packages those credentials into structured logs alongside the URLs where each credential was captured. Threat actors then aggregate these logs and publish them on underground forums, either for sale or as free releases to build reputation. Because the data is collected directly from the infected device, passwords appear in plaintext exactly as the user typed or saved them.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including stealer log databases like this one. Run a free scan now at heroic.com to find out if your credentials appeared in this or any related LeakBase release.
Related Parts of This Breach
- LeakBase 10Kk ULP by firegoon
- LeakBase 10.5Kk ULP by firegoon
- LeakBase 22Kk ULP by firegoon
- LeakBase 4.3Kk ULP by firegoon
- LeakBase 15Kk ULP #4 by firegoon
- LeakBase 15Kk ULP #3 by firegoon
- LeakBase 20Kk ULP (part 2) by firegoon
- LeakBase 7Kk ULP by firegoon
- LeakBase 8.7M ULP by firegoon
- LeakBase 5.6Kk ULP by firegoon
Breach Breakdown
2,682,689 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds