The LeakBase 8GB ULP Dump: 46.6 Million Stolen Login Credentials Hit Underground Forums
On October 9, 2024, a stealer log known as the "8GB ULP" was uploaded to a prominent underground hacking forum by threat actor 19890036580. The raw archive contained an extraordinary 200,001,000 records. After deduplication, researchers identified 46,650,456 unique email addresses, each paired with a plaintext password and the homepage URL of the service where the credential was captured. This is one of the largest credential stealer log releases of October 2024 -- and because every password is in plaintext, every single pair is immediately usable for account takeover attacks without any additional cracking.
Why This Is Dangerous
The scale of this dump is exceptional even by stealer log standards. With nearly 47 million unique email addresses and corresponding plaintext passwords, this dataset gives attackers a massive, ready-to-use arsenal for automated credential stuffing campaigns. The inclusion of homepage URLs means attackers already know which service each password unlocks -- dramatically lowering the effort required to compromise individual accounts. Large compilations like this are also sold or traded, meaning the data circulates far beyond its original posting point.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL (the specific site where the credential was used)
Why This Matters
- Credential stuffing at scale: 46.6 million validated email/password pairs fuel automated attacks against banks, email providers, social networks, and e-commerce platforms.
- Immediate account takeover: Plaintext passwords require zero cracking -- attackers can begin testing credentials the moment they download the file.
- Password reuse chain reaction: One compromised password often unlocks multiple accounts across different services, multiplying the damage from a single exposure.
- Identity theft and fraud: Gaining access to email accounts in particular lets attackers reset passwords for linked financial services, social media, and cloud storage.
How Stealer Logs Work
Infostealer malware is distributed through malicious downloads, phishing emails, fake software cracks, and drive-by browser exploits. Once installed on a victim's machine, it silently captures credentials stored in browsers and password managers, session cookies, and autofill data -- all in plaintext, before encryption occurs. That data is transmitted to an attacker-controlled server, aggregated into large log files, and posted to underground forums for sale or free distribution. Because the capture happens client-side, server-side security measures like password hashing offer no protection.
Check If You Are Affected
If your device has ever been infected with malware -- even briefly -- your credentials may appear in a stealer log like this one. HEROIC monitors over 400 billion breached records, including stealer log compilations, so you can search your email address and find out immediately.
Breach Breakdown
46,650,456 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds