LeakBase Horizon Clouds 100M ULP Is Bigger Than Most Data Breaches
HEROIC analysts identified a stealer log posted to LeakBase on July 30, 2024 by threat actor 1212123, catalogued as "Horizon Clouds 100M ULP." Despite its name suggesting 100 million records, the actual dataset contained approximately 36 million lines and exposed 1,681,302 unique email addresses paired with plaintext passwords and associated HomePage URLs. The post was subsequently removed from the forum, though removal does not limit the data's ongoing circulation among threat actors. This release is part of a coordinated multi-part dumping campaign by the same actor, which also includes LeakBase 20M ULP by 1212123, LeakBase 30M ULP by 1212123, LeakBase 40M ULP by 1212123, LeakBase 70M ULP by 1212123, LeakBase Horizon Clouds 40M ULP by 1212123, and LeakBase Beast 60M ULP by 1212123.
With 1.68 million email and plaintext password pairs available in a ready-to-use ULP format, attackers can immediately launch automated credential stuffing campaigns across any online service without a single decryption step. The HomePage URLs embedded alongside each credential record give threat actors a profile of each victim's online activity, enabling targeted phishing messages, account prioritization based on which services hold the most financial or personal value, and potential reconnaissance into corporate environments if work-related sites appear in the URL history.
What Was Exposed
- Email addresses
- Plaintext passwords
- HomePage URLs
Why This Matters
Over 1.6 million plaintext credentials in a single log means that for every affected individual, every service where they reused that password is now at risk simultaneously. Credential stuffing tools can test these pairs against dozens of platforms in parallel, meaning account takeovers at banks, email providers, healthcare portals, and workplace systems can unfold within hours of a log being posted. From compromised accounts, attackers escalate to identity theft, fraudulent wire transfers, SIM-swap attacks, and social engineering of coworkers or family members.
How Stealer Log Leaks Work
Infostealer malware infects a victim's device through phishing emails, trojanized software installers, or malicious browser extensions. Once running, the malware extracts saved usernames and passwords directly from browser storage, records the URLs associated with each credential, and transmits everything to an attacker-controlled server. The captured data is formatted into URL-login-password (ULP) files optimized for bulk import into credential stuffing tools. These files are then posted or sold on hacking forums like LeakBase, where they spread rapidly even after the original post is removed.
Check If You Are Affected
HEROIC's free breach scanner checks your email address against more than 400 billion exposed records, including stealer log data like this LeakBase Horizon Clouds 100M ULP dump. Run a free scan now to find out whether your credentials were included and get concrete steps to lock down your accounts before attackers act.
Related Parts of This Breach
Breach Breakdown
1,681,302 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds