5.3 Million Records Exposed in LeakBase HRLT Cloud 40M ULP Breach
HEROIC analysts found that on July 17, 2024, a stealer log titled "HRLT Cloud 40M ULP" was posted on a prominent underground hacking forum by the threat actor savbal. The log exposed 5,337,992 unique records containing email addresses, plaintext passwords, and HomePage URLs harvested from compromised user devices. The plaintext nature of the passwords means credentials are immediately usable by anyone who obtains this data, with no cracking required. The country most affected is the United States.
Why This Is Dangerous
Stealer logs containing plaintext passwords represent one of the most immediately actionable threat categories in cybersecurity. Unlike hashed credential dumps that require time-consuming cracking, plaintext credentials can be deployed in automated attacks within minutes of a leak going public. With 5,337,992 exposed records tied to real email and URL pairs, attackers can identify exactly which services a victim uses and target those accounts directly.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
Credential stuffing attacks rely on the widespread human habit of reusing passwords across multiple services. When a leak like this surfaces, automated bots systematically test the exposed email-and-password pairs against banking portals, email providers, e-commerce platforms, and social networks. A single reused password can result in account takeover (ATO) across dozens of services, opening victims to financial fraud, identity theft, unauthorized purchases, and account lockout. The included HomePage URLs further help attackers prioritize which accounts to target first.
How Database Breaches Work
A database breach of this type originates from infostealer malware deployed on end-user devices. Once installed, the malware silently harvests credentials stored in browsers, email clients, and other applications, along with the URLs those credentials are associated with. The collected data is aggregated into logs and sold or published on underground forums. Because the source is the user's own device rather than a single organization's server, these logs pull credentials from dozens or hundreds of different services simultaneously, making them especially damaging.
Check If You Are Affected
HEROIC offers a free dark web scanner that searches across more than 400 billion compromised records to check whether your email address appears in known breach data, including stealer logs like this one. If your credentials were exposed in the LeakBase HRLT Cloud 40M ULP leak, changing your passwords immediately and enabling two-factor authentication on all accounts is critical. Visit heroic.com to run a free scan now.
Breach Breakdown
5,337,992 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds