LeakBase Fresh ULP by Styles20: 59K Plaintext Passwords Exposed
HEROIC analysts identified a credential dump posted on a prominent underground forum on June 30, 2024, attributed to the threat actor Styles20 and distributed under the LeakBase label as "Fresh ULP." The exposure affected 59,330 individuals, with each record containing an email address, a plaintext password, and the account holder's last name. The absence of any password hashing means every credential in this dataset is immediately actionable by any attacker who obtains it.
Why This Is Dangerous
Plaintext passwords require no cracking. The moment this dataset circulated on underground forums, every affected account became trivially accessible. Attackers can load these credentials directly into automated tools and attempt logins across hundreds of services within minutes. The inclusion of last names adds a social engineering dimension, enabling targeted phishing and account recovery attacks that go beyond simple credential stuffing.
What Was Exposed
- Email addresses
- Plaintext passwords
- Last names
Why This Matters
Credential stuffing attacks powered by plaintext dumps like this one are responsible for a large share of account takeover (ATO) incidents recorded each year. Once attackers gain access to a single account, they pivot to financial fraud, identity theft, and further credential harvesting. Victims whose last names are included face compounded risk: attackers can craft highly convincing spear-phishing messages or impersonate victims to bypass knowledge-based authentication challenges. Any person who reused the exposed password on another service faces immediate and concrete danger.
How Database Breaches Work
A database breach occurs when an attacker gains unauthorized access to a backend data store, typically through SQL injection, exploitation of misconfigured database ports, compromised administrative credentials, or vulnerabilities in third-party software dependencies. Once inside, the attacker exports user tables containing authentication records. When those records include plaintext passwords rather than properly salted hashes, the exfiltrated data provides instant, ready-to-use credentials. This contrasts with properly secured databases where even a successful exfiltration yields only hashed values that require significant computational effort to reverse.
Check If You Are Affected
HEROIC operates a free identity scanner backed by a database of over 400 billion compromised records. If your email address appeared in the LeakBase Fresh ULP by Styles20 dataset or any other known breach, the scanner will surface that exposure immediately. Search your email now at heroic.com to find out whether your credentials are circulating on the dark web and take action before an attacker does.
Breach Breakdown
59,330 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds