Breach Intelligence Report 24 Nov 2024

The LeakBase RLREBORN 60M ULP Dump: 14 Million Stolen Login Credentials Posted to a Hacking Forum

HEROIC
HEROIC Threat Intelligence Team
Email Address Homepage Url Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 14,036,788
Source Type Database
Origin Darkweb
Password Type Plaintext

On November 7, 2024, a credential collection titled "60,117,230 Lines Fresh Lines Valid Private ULP @Rlreborn P32" was posted to a prominent hacking forum under the LeakBase umbrella. The dataset, attributed to a threat actor known as FATHER121, contained over 60 million raw records formatted as URL-login-password (ULP) triples -- each line associating a website, an email address, and a plaintext password. After deduplication, the dataset yielded 14,036,788 unique email and password pairs. Those credentials are immediately usable in automated credential-stuffing attacks against any site where the password was reused.

This dataset is part of a broader ecosystem of LeakBase-hosted stealer log dumps. Related collections from the same forum include LeakBase 153Kk ULP 2023 by Chucky (21.7 million unique credentials) and LeakBase Beast 60M ULP by 1212123 -- each sourced from infostealer malware campaigns and posted separately by different threat actors.


Why This Is Dangerous

Plaintext passwords require no additional processing. The moment this dataset was posted, any actor who downloaded it could immediately begin testing credentials against email providers, banking sites, corporate VPNs, and cloud services. The homepage URLs in the dataset tell attackers exactly which site each credential came from -- allowing targeted attacks against the highest-value services rather than broad untargeted stuffing. At 14 million unique pairs, even a conservative success rate produces hundreds of thousands of compromised accounts.


What Was Exposed

  • Email addresses (14,036,788 unique records)
  • Plaintext passwords
  • Homepage URLs (the originating site for each harvested credential)

Total raw lines in the dump: approximately 60,117,230.


Why This Matters

Stealer log datasets like this one drive a significant portion of account compromises across the internet:

  • Credential stuffing: Automated tools systematically test each email/password pair across thousands of popular sites, exploiting the widespread habit of password reuse.
  • Account takeover: Successful logins hand attackers access to email inboxes, financial accounts, cloud storage, and corporate systems -- all without triggering fraud alerts tied to unknown passwords.
  • Identity theft: Email account access is a skeleton key -- it enables password resets across any service that recognizes that address, leading to full identity compromise.
  • Fraud: Compromised accounts are used to make fraudulent purchases, initiate wire transfers, or resell access on dark web markets.

How Stealer Logs Work

Infostealer malware infects a victim's device -- typically through phishing emails, malicious downloads, or compromised software installers -- and silently harvests credentials stored in browsers, password managers, and application sessions. Every saved password on the device is exfiltrated to the attacker's server. These credentials are aggregated across thousands of infected devices, formatted as ULP lists (URL, login, password), and sold or posted on forums. The "RLREBORN" designation refers to a specific collection or campaign name used to market the dump; "60M" refers to the approximately 60 million raw lines in the file before deduplication.


Check If You Are Affected

If your email address is in this dataset, your password for at least one website was harvested by infostealer malware and is now available to any attacker who downloaded this dump. HEROIC's breach database contains over 400 billion compromised records. Search now to find out if your credentials appear in this or any other known breach -- and change any reused passwords immediately.

Search HEROIC's 400B+ breach database now


Related Parts of This Breach

The LeakBase forum hosts multiple ULP stealer log collections posted by different threat actors. Other datasets from this ecosystem:

Breach Breakdown

Domain N/A
Leaked Data Email Address, HomePage URL, Plaintext Password
Password Types Plaintext
Date Leaked 24 Nov 2024
Check in 5 seconds

14,036,788 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,998 scanned today
Breach Rank #236 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $101.6M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance