Breach Intelligence Report 17 Jan 2025

Stealer Log Users Exposed: LeakBase NewDatabase 18M ULP Leaked 771K Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Address Homepage Url Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 771,397
Source Type Database
Origin Darkweb
Password Type Plaintext

On December 19, 2024, a threat actor operating under the handle farmagol posted a large credential dump on a prominent cybercrime forum under the name "LeakBase NewDatabase 18M ULP." The dataset claimed to contain approximately 18 million records, and analysis confirmed 771,397 unique email and password combinations within it. What makes this incident especially dangerous is the format of the passwords: they are plaintext, meaning no cracking is required. Any attacker who downloaded this dump can immediately attempt logins across email providers, banks, social media platforms, and shopping sites using the exposed credentials. Stealer log dumps of this scale represent one of the most direct and immediate threats to consumer account security.


What Was Exposed in the LeakBase NewDatabase 18M ULP Breach

  • Email Address - the primary account identifier, used to target logins across all major platforms
  • Plaintext Password - requires zero cracking; immediately usable by any attacker who downloads the dataset
  • HomePage URL - reveals the websites or services the victim was logged into when the malware was active, enabling targeted follow-on attacks

Why This Matters

Plaintext passwords in a leaked dataset are the worst-case scenario for affected users. There is no grace period while attackers attempt to crack hashes: credentials can be tested against hundreds of services the moment the dump is downloaded. Criminals run automated credential stuffing tools that attempt logins across email, banking, e-commerce, and social media platforms within minutes. A single successful login to an email account can trigger a chain reaction: password resets sent to that inbox give attackers access to every linked service, enabling fraud, identity theft, and financial loss. The HomePage URLs also reveal which sites each victim actively used, allowing attackers to prioritize the most valuable targets rather than spraying credentials blindly.


How Stealer Log Malware Works

Stealer malware is a category of malicious software designed to silently harvest saved credentials, browser cookies, autofill data, and active session tokens from infected computers. It typically spreads through phishing emails, malicious software downloads, cracked games or applications, and compromised websites. Once installed, it runs in the background and captures login data as the victim browses normally, packaging everything into a log file that is automatically sent to the attacker. These logs are then compiled, deduplicated, and sold or posted on forums in bulk datasets called ULP (URL-Login-Password) files. The victim usually has no idea their credentials were stolen until accounts begin showing unauthorized access.


Check If You Are Affected

HEROIC's identity monitoring service searches across more than 400 billion exposed records, including stealer logs, credential dumps, and dark web datasets. If your email address or password appeared in the LeakBase NewDatabase 18M ULP dump or any related stealer log, HEROIC will alert you immediately so you can change your passwords and secure your accounts before attackers strike. Run a free scan at HEROIC.com to find out if your credentials are exposed.

Breach Breakdown

Domain N/A
Leaked Data Email Address, HomePage URL, Plaintext Password
Password Types Plaintext
Date Leaked 17 Jan 2025
Check in 5 seconds

771,397 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,733 scanned today
Breach Rank #1,866 by affected users
Impact Score
31
sensitivity + scale + recency
Est. Financial Impact $5.6M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance