LeakBase RLREBORN 60Kk ULP: 10.9M Passwords Exposed. Check Yours Now.
In October 2024, a threat actor known as "farmagol" posted a stealer log to a well-known hacking forum under the name "60Kk ULP (Not Own)" -- part of the ongoing LeakBase RLREBORN series of credential dumps. The post contained 60 million raw records, of which 10,928,093 were unique. What makes this release particularly dangerous is the inclusion of plaintext passwords: credentials that require no cracking, no decryption, and no guesswork. If your email and password appear in this dataset, any attacker who downloads it can log into your accounts immediately.
This release is part of a larger series of RLREBORN stealer log dumps circulating on underground forums. See related releases below.
Why This Is Dangerous
Stealer logs are harvested by malware installed on infected devices. Unlike database breaches where a company's server is hacked, stealer logs capture credentials directly from the victim's browser at the moment of login. This means the email and password pairs in this dataset were working, active credentials at the time of harvest. Plaintext storage means no cracking step -- attackers can use these credentials immediately for account takeover across any service where you reuse that password.
What Was Exposed
- Email addresses (10,928,093 unique records) -- primary attack identifier for account access and phishing
- Plaintext passwords -- harvested directly, no cracking required, immediately usable for login
- Homepage URLs -- reveal which websites the victim visited or logged into, enabling targeted attacks
Why This Matters
Plaintext credential leaks at this scale fuel cascading attacks across the internet. Threat actors use these datasets to:
- Credential stuff hundreds of popular platforms simultaneously, achieving account takeovers at scale
- Take over accounts on banking, shopping, email, and social media platforms where passwords were reused
- Commit identity theft using account access to harvest additional personal and financial details
- Enable fraud by accessing payment methods, making purchases, or draining accounts directly
How Stealer Logs Work
Stealer malware (also called infostealer or credential stealer) infects a victim's device through phishing emails, malicious downloads, cracked software, or compromised websites. Once installed, it silently monitors browser activity and extracts saved credentials, session cookies, and autofill data. The harvested data is bundled into logs and sold or posted on hacking forums. The "60Kk ULP" designation (URL:Login:Password) describes the format -- each line contains a website URL paired with an email address and its corresponding password. These logs are then loaded into credential stuffing tools and fired against login forms across the web at machine speed.
Check If You Are Affected
HEROIC's dark web monitoring database contains over 400 billion exposed records, including stealer log compilations like this RLREBORN release. If your credentials appeared in this dump or any related release, you can find out now. Search the HEROIC database and change any reused passwords immediately -- before an attacker beats you to it.
Related Parts
This breach is part of the LeakBase RLREBORN series of stealer log releases. Other known releases include:
- LeakBase Private RLREBORN 487MB ULP by farmagol
- LeakBase RLREBORN 5.8M ULP by farmagol
- The LeakBase RLREBORN 60M ULP Dump: 14 Million Stolen Login Credentials Posted to a Hacking Forum
- The LeakBase RLREBORN 200M ULP Breach Put 12.9 Million Stolen Email and Password Pairs Online
- FATHER121 Dropped 5.9M Logins: Inside the LeakBase RLREBORN 45.5M ULP
Breach Breakdown
10,928,093 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds