Who farmagol’s LeakBase Benczus 83Kk ULP Targets: 12.7M Plaintext Credentials Exposed
HEROIC analysts identified the LeakBase Benczus Logs 83Kk ULP by farmagol stealer log on June 1, 2024, confirming 12,768,637 unique email addresses exposed alongside plaintext passwords and homepage URLs. This log is one of many in the ongoing series of credential dumps attributed to threat actor farmagol and distributed on underground forums. Related releases in this series include the LeakBase 32Kk ULP by farmagol, the LeakBase 50Kk ULP by farmagol, and LeakBase 95Kk ULP by farmagol, among others. The scale of this particular dump, sourced from infostealer malware rather than a single organization's database, means that victims span industries, geographies, and account types.
Why This Is Dangerous
Plaintext passwords require no cracking. Every record in this stealer log is immediately actionable: an attacker loads the email-and-password pairs into automated credential stuffing tools and tests them against banking portals, email providers, social media platforms, and corporate VPNs within hours of obtaining the data. Because infostealer malware captures credentials from the browser at the moment of entry, the passwords are current at the time of theft, not hashed representations of historical choices.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
Stealer logs with plaintext credentials are among the most dangerous breach categories because they enable immediate account takeover without any additional effort. Credential stuffing attacks powered by this data compromise email inboxes, which in turn allow attackers to reset passwords on every linked service. Account takeover cascades into identity theft as attackers access financial accounts, file fraudulent tax returns, and sell verified account access to other criminals. The homepage URLs also tell attackers exactly which services each victim was actively using, enabling targeted follow-on attacks.
How Stealer Logs Work
Stealer logs are produced by infostealer malware installed on victims' computers, typically through phishing emails, malicious downloads, or compromised software. Once active, the malware captures usernames and passwords directly from web browsers and applications as they are entered, records the associated website URLs, and transmits this data to attacker-controlled servers. The attacker then compiles these records into large log files and sells or publishes them on underground forums. Because credentials are captured live, the passwords are current and highly reliable for subsequent attacks.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion compromised records to tell you whether your email address appears in the LeakBase Benczus Logs 83Kk ULP breach or any other known data leak. Visit heroic.com to run a free scan now. If your email is found, change all passwords associated with that address immediately, enable two-factor authentication on every account, and run a reputable antivirus scan to ensure your device is not currently infected with infostealer malware.
Related Parts of This Breach
Threat actor farmagol has published numerous stealer log dumps in the LeakBase ULP series. Other confirmed releases include:
- LeakBase 32Kk ULP by farmagol - 4,135,894 records
- LeakBase 50Kk ULP by farmagol - 8,538,568 records
- LeakBase 95Kk ULP by farmagol - 13.7 million records
- LeakBase 14Kk ULP by farmagol - 3.53 million records
- LeakBase 18Kk ULP by farmagol - 1,647,896 records
Breach Breakdown
12,768,637 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds