Stealer Log Users Exposed: LeakBase NewDatabase 18M ULP Leaked 771K Credentials
On December 19, 2024, a threat actor operating under the handle farmagol posted a large credential dump on a prominent cybercrime forum under the name "LeakBase NewDatabase 18M ULP." The dataset claimed to contain approximately 18 million records, and analysis confirmed 771,397 unique email and password combinations within it. What makes this incident especially dangerous is the format of the passwords: they are plaintext, meaning no cracking is required. Any attacker who downloaded this dump can immediately attempt logins across email providers, banks, social media platforms, and shopping sites using the exposed credentials. Stealer log dumps of this scale represent one of the most direct and immediate threats to consumer account security.
What Was Exposed in the LeakBase NewDatabase 18M ULP Breach
- Email Address - the primary account identifier, used to target logins across all major platforms
- Plaintext Password - requires zero cracking; immediately usable by any attacker who downloads the dataset
- HomePage URL - reveals the websites or services the victim was logged into when the malware was active, enabling targeted follow-on attacks
Why This Matters
Plaintext passwords in a leaked dataset are the worst-case scenario for affected users. There is no grace period while attackers attempt to crack hashes: credentials can be tested against hundreds of services the moment the dump is downloaded. Criminals run automated credential stuffing tools that attempt logins across email, banking, e-commerce, and social media platforms within minutes. A single successful login to an email account can trigger a chain reaction: password resets sent to that inbox give attackers access to every linked service, enabling fraud, identity theft, and financial loss. The HomePage URLs also reveal which sites each victim actively used, allowing attackers to prioritize the most valuable targets rather than spraying credentials blindly.
How Stealer Log Malware Works
Stealer malware is a category of malicious software designed to silently harvest saved credentials, browser cookies, autofill data, and active session tokens from infected computers. It typically spreads through phishing emails, malicious software downloads, cracked games or applications, and compromised websites. Once installed, it runs in the background and captures login data as the victim browses normally, packaging everything into a log file that is automatically sent to the attacker. These logs are then compiled, deduplicated, and sold or posted on forums in bulk datasets called ULP (URL-Login-Password) files. The victim usually has no idea their credentials were stolen until accounts begin showing unauthorized access.
Check If You Are Affected
HEROIC's identity monitoring service searches across more than 400 billion exposed records, including stealer logs, credential dumps, and dark web datasets. If your email address or password appeared in the LeakBase NewDatabase 18M ULP dump or any related stealer log, HEROIC will alert you immediately so you can change your passwords and secure your accounts before attackers strike. Run a free scan at HEROIC.com to find out if your credentials are exposed.
Breach Breakdown
771,397 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds