Everyday Internet Users Are the Target: The LeakBase 95Kk ULP Breach Dumped 13.7 Million Plaintext Passwords
Threat actor farmagol posted a stealer log to underground hacking forums on October 1, 2024, under the name "95Kk ULP." The file contained roughly 95 million total records, of which 13,754,906 were unique email-and-password pairs. What makes this release particularly damaging is that all passwords are in plaintext. There is no hashing, no cracking required. Any attacker who downloaded the file had working credentials ready to use immediately. Farmagol signed off on the post with a cheerful "Good luck!" to the forum audience, signaling that the data was being widely distributed for use in credential stuffing campaigns.
This release is part of a larger series of ULP (URL-Login-Password) stealer log dumps by farmagol on LeakBase. See related releases:
- 2 Million Plaintext Passwords From the LeakBase 5Kk ULP by Farmagol
- LeakBase 50M ULP by farmagol
- LeakBase 50M ULP Part 2 by farmagol
- LeakBase 32Kk ULP by farmagol
Why This Is Dangerous
Stealer logs are harvested by malware running silently on infected devices. The malware captures everything typed into login fields, along with the URL of the site, and sends the credentials back to the attacker's infrastructure. The result is a file where every row contains a real URL, a real email address, and the real password the user typed. Because these credentials were captured live from working sessions, they are highly accurate and immediately usable. Plaintext passwords from stealer logs are among the most valuable and damaging datasets in circulation on dark web forums.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL (the site where the credentials were captured)
Why This Matters
The real harm of this breach cascades well beyond the individual sites where passwords were stolen:
- Credential stuffing: Automated tools test each email/password pair across thousands of other platforms simultaneously. A password stolen from a gaming site unlocks your bank if you reused it.
- Account takeover: Once inside an account, attackers can change recovery emails, drain balances, or sell the access on secondary markets.
- Identity theft: Email account access is a skeleton key. From a compromised inbox, attackers reset passwords on every linked service and access years of personal and financial information.
- Fraud: Payment methods stored in compromised accounts are used for purchases, or sold directly to fraud networks.
How Stealer Log Breaches Work
Unlike a traditional breach where an attacker hacks a company's server, stealer logs originate on the victim's own device. Malware is delivered via phishing emails, pirated software, or malicious browser extensions. Once installed, it silently records keystrokes and captures credentials from autofill. The harvested data is bundled into log files and sold or posted on underground forums by the malware operator. Because the malware captures data from multiple sites per device, a single infection can yield dozens of usable credentials for one person across many platforms.
Check If You Are Affected
Heroic indexes over 400 billion breached records, including stealer log compilations like this one from farmagol. Search now to find out if your email address appears in this or any related ULP dump.
Search 400+ Billion Breached Records at Heroic
Related Parts
Breach Breakdown
13,754,906 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds