The LeakBase RLREBORN 60M ULP Dump: 14 Million Stolen Login Credentials Posted to a Hacking Forum
On November 7, 2024, a credential collection titled "60,117,230 Lines Fresh Lines Valid Private ULP @Rlreborn P32" was posted to a prominent hacking forum under the LeakBase umbrella. The dataset, attributed to a threat actor known as FATHER121, contained over 60 million raw records formatted as URL-login-password (ULP) triples -- each line associating a website, an email address, and a plaintext password. After deduplication, the dataset yielded 14,036,788 unique email and password pairs. Those credentials are immediately usable in automated credential-stuffing attacks against any site where the password was reused.
This dataset is part of a broader ecosystem of LeakBase-hosted stealer log dumps. Related collections from the same forum include LeakBase 153Kk ULP 2023 by Chucky (21.7 million unique credentials) and LeakBase Beast 60M ULP by 1212123 -- each sourced from infostealer malware campaigns and posted separately by different threat actors.
Why This Is Dangerous
Plaintext passwords require no additional processing. The moment this dataset was posted, any actor who downloaded it could immediately begin testing credentials against email providers, banking sites, corporate VPNs, and cloud services. The homepage URLs in the dataset tell attackers exactly which site each credential came from -- allowing targeted attacks against the highest-value services rather than broad untargeted stuffing. At 14 million unique pairs, even a conservative success rate produces hundreds of thousands of compromised accounts.
What Was Exposed
- Email addresses (14,036,788 unique records)
- Plaintext passwords
- Homepage URLs (the originating site for each harvested credential)
Total raw lines in the dump: approximately 60,117,230.
Why This Matters
Stealer log datasets like this one drive a significant portion of account compromises across the internet:
- Credential stuffing: Automated tools systematically test each email/password pair across thousands of popular sites, exploiting the widespread habit of password reuse.
- Account takeover: Successful logins hand attackers access to email inboxes, financial accounts, cloud storage, and corporate systems -- all without triggering fraud alerts tied to unknown passwords.
- Identity theft: Email account access is a skeleton key -- it enables password resets across any service that recognizes that address, leading to full identity compromise.
- Fraud: Compromised accounts are used to make fraudulent purchases, initiate wire transfers, or resell access on dark web markets.
How Stealer Logs Work
Infostealer malware infects a victim's device -- typically through phishing emails, malicious downloads, or compromised software installers -- and silently harvests credentials stored in browsers, password managers, and application sessions. Every saved password on the device is exfiltrated to the attacker's server. These credentials are aggregated across thousands of infected devices, formatted as ULP lists (URL, login, password), and sold or posted on forums. The "RLREBORN" designation refers to a specific collection or campaign name used to market the dump; "60M" refers to the approximately 60 million raw lines in the file before deduplication.
Check If You Are Affected
If your email address is in this dataset, your password for at least one website was harvested by infostealer malware and is now available to any attacker who downloaded this dump. HEROIC's breach database contains over 400 billion compromised records. Search now to find out if your credentials appear in this or any other known breach -- and change any reused passwords immediately.
Search HEROIC's 400B+ breach database now
Related Parts of This Breach
The LeakBase forum hosts multiple ULP stealer log collections posted by different threat actors. Other datasets from this ecosystem:
- LeakBase 153Kk ULP 2023 by Chucky -- 21.7M unique credentials
- LeakBase Beast 60M ULP by 1212123
- LeakBase ULP by vaxima
Breach Breakdown
14,036,788 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds