Attackers Can Log In Instantly: LeakBase Styles20 ULP Exposes 157K Plaintext Credentials
HEROIC analysts found 157,403 records from the LeakBase 1.3M ULP by Styles20 dataset circulating on a prominent hacking forum as of July 1, 2024. The poster described the data as fresh, a label that signals credentials collected from recently infected devices and not yet widely tested against target accounts. The exposed records include email addresses, plaintext passwords, and homepage URLs harvested by infostealer malware. This release is one of hundreds of credential compilations posted to the LeakBase forum community, alongside related dumps such as LeakBase 1.8k Logs by MalikHamza, LeakBase 10Kk ULP by firegoon, and LeakBase Beast 60M ULP by 1212123.
Why This Is Dangerous
Plaintext passwords require zero effort from an attacker. The moment this dataset was posted, anyone who downloaded it could immediately attempt logins across email providers, banking platforms, social media, and e-commerce sites using the exposed email-and-password pairs. Homepage URLs embedded in the log reveal which websites the victims actively use, enabling attackers to prioritize the highest-value account takeover attempts first. The combination of ready-to-use credentials and a map of victim activity makes this dataset significantly more dangerous than a typical breach.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
With plaintext credentials and homepage URLs in hand, attackers can execute credential stuffing attacks at scale, automatically testing each email-and-password pair against hundreds of platforms simultaneously. Successful logins enable account takeover (ATO), which can result in unauthorized financial transactions, theft of stored payment methods, fraudulent purchases, and identity theft. Attackers who gain access to email accounts can then trigger password resets across every other service the victim uses, creating a cascading compromise. Homepage URLs also enable highly targeted phishing, since attackers know exactly which brands a victim trusts.
How Stealer Logs Work
A stealer log is the output of infostealer malware running silently on a victim's device. The malware is typically delivered through phishing emails, trojanized software downloads, or malicious browser extensions. Once installed, it captures saved credentials from browsers, autofill data, and session tokens, then transmits everything to a command-and-control server. The aggregated data is packaged as a ULP (URL-Login-Password) list and sold or posted on forums like LeakBase. ULP format is particularly dangerous because each record links a specific website to a specific username and password, eliminating guesswork for attackers.
Check If You Are Affected
HEROIC's free breach scanner searches more than 400 billion compromised records to determine instantly whether your email address appears in stealer log datasets, including this Styles20 release and related LeakBase compilations. Run a free scan at heroic.com to find out if your credentials are exposed and change any compromised passwords immediately.
Related Parts of This Breach
This release is part of a broader series of credential dumps posted to the LeakBase forum community by multiple threat actors. Related releases include:
Breach Breakdown
157,403 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds