Your Saved Password Was Already Stolen: The farmagol RLREBORN Leak
HEROIC analysts confirmed a stealer log identified as LeakBase RLREBORN 5.8M ULP by farmagol, surfacing on July 1, 2024, containing 335,344 unique exposed records. Picture this: you log into a familiar website, using the same email and password you have used for years. Somewhere in the background, an infostealer malware already harvested those credentials from your device weeks earlier. Now that email and password sit inside this dataset, packaged alongside the homepage URL of the site you logged into, ready for automated tools to replay across your bank, your email, and your workplace accounts. That is the precise threat this breach represents for everyone in its 335,344 records.
Why This Is Dangerous
Stealer logs are compiled from infostealer malware infections on individual devices. The threat actor farmagol assembled and published this dataset containing plaintext passwords, meaning no cracking is required. The inclusion of homepage URLs alongside credentials gives attackers a ready-made targeting map: they know exactly which services to attempt the stolen credentials against. The combination of immediate usability and site-specific targeting makes this stealer log exceptionally high-risk for account takeover and downstream fraud.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
Credential stuffing attacks powered by stealer log data are among the most automated and scalable threats in the current threat landscape. Attackers feed email and password pairs into credential stuffing tools that test them across hundreds of platforms simultaneously. Successful logins result in account takeover, which is then leveraged for financial fraud, identity theft, unauthorized purchases, and lateral movement into corporate systems. The homepage URL field compounds this risk by enabling targeted, service-specific attacks rather than broad spray campaigns.
How Stealer Logs Work
A stealer log breach does not originate from a single company's database being hacked. Instead, infostealer malware, distributed through phishing emails, malicious downloads, or compromised software, infects individual user devices and silently harvests saved credentials from browsers, password managers, and active sessions. The stolen data is sent to a command-and-control server, aggregated, and then sold or published on underground forums. The actor farmagol has published multiple compilations of this type, each containing credentials harvested from infected devices across a range of services and geographies.
Check If You Are Affected
Because stealer logs draw from many different sources, your credentials may appear here even if you have never used a compromised company's platform directly. HEROIC's free dark web scanner searches more than 400 billion exposed records, including stealer log compilations. Run a free scan at heroic.com to find out whether your email address has appeared in this release or any of farmagol's other publications.
Related Parts of This Breach
The actor farmagol has published multiple stealer log compilations on underground forums. Other confirmed releases in this series include:
- LeakBase Private RLREBORN 487MB ULP by farmagol
- LeakBase RLREBORN 60Kk ULP by farmagol
- LeakBase 50M ULP by farmagol
- LeakBase 50M ULP Part 2 by farmagol
- LeakBase 32Kk ULP by farmagol
- LeakBase Benczus Logs 83Kk ULP by farmagol
- LeakBase Sesupe 200M ULP by farmagol
- LeakBase Sesupe 200M ULP 2 by farmagol
- LeakBase 50Kk ULP by farmagol
- LeakBase 5Kk ULP by farmagol
Breach Breakdown
335,344 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds