Dark Web Intel: LeakBase 80M+ ULP by Ffish Dumped 14.2M Credentials
On November 1, 2024, a threat actor posted a dataset called "80Million+ Url Login Pass" on a well-known hacking forum under the LeakBase banner. The compressed archive weighed in at 1.93 GB (5.71 GB uncompressed) and contained more than 80 million records, of which approximately 14.26 million were unique. What makes this dump particularly severe is the presence of plaintext passwords alongside email addresses and associated URLs, meaning anyone who downloads the file can immediately attempt to log in to the services listed without any cracking or decryption step. This collection is part of a broader ecosystem of stealer log dumps distributed through LeakBase, a forum identity used repeatedly to release aggregated credential sets harvested from compromised devices and applications.
Why This Is Dangerous
Plaintext passwords require no additional processing. Unlike hashed credentials that must be cracked before use, these are ready to deploy in automated credential-stuffing attacks the moment the file is downloaded. Stealer logs of this type are compiled from malware infections on end-user devices, meaning the passwords captured were still active at the time of theft. Even if a user has since changed their password on the directly compromised service, the same password is statistically likely to still be in use elsewhere, making every site in the affected person's digital footprint a potential target.
What Was Exposed
- Email Addresses - 14.26 million unique addresses, the primary identifier for account takeover attempts
- Plaintext Passwords - ready to use without cracking, the highest-severity credential type
- Homepage URLs - identify exactly which services the stolen credentials belong to, enabling targeted login attempts
Why This Matters
Stealer log dumps like this one fuel a cascade of downstream attacks:
- Credential stuffing - Automated tools test each email-password pair across banking, retail, email, and social media platforms in minutes.
- Account takeover - Attackers who gain access to one account pivot to linked accounts, often resetting passwords using the compromised email inbox.
- Identity theft - Once inside an email account, attackers find verification codes, financial statements, and personal correspondence they can weaponize.
- Fraud - Compromised financial accounts and e-commerce profiles are drained or used to make unauthorized purchases.
How Stealer Logs Work
Stealer logs are compiled by malware, known as information stealers or infostealers, that silently runs on a victim's computer after being delivered via phishing emails, malicious downloads, or compromised software. Once installed, the malware scrapes saved passwords from browsers, credential vaults, and active sessions, then transmits the data to a command-and-control server. The attacker collects these logs from infected machines over time, aggregates them into large files, and either sells the collection privately or posts it publicly to build forum reputation. The "by Ffish" designation in this dump's title indicates the specific actor or aggregator responsible for compiling and distributing this particular collection within the LeakBase ecosystem.
Check If You Are Affected
If your email address appears in this dump, your password for at least one service was exposed in plaintext and may already be in use by threat actors. You should change passwords immediately, enable multi-factor authentication on all accounts, and review your inbox for signs of unauthorized access. Heroic's breach search engine indexes over 400 billion compromised records, including stealer log collections like this one.
Search your email now at Heroic.com to find out whether your credentials appeared in this dump or any other known leak.
Related LeakBase Dumps
This release is part of an ongoing series of credential dumps distributed through LeakBase. Other related collections include:
Breach Breakdown
14,264,365 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds