Utah Parent Center Logo Brining Hope, Opening Doors, Elevating Inclusion
HEROIC Mega Menu
Breach Intelligence Report 31 Oct 2024

Dark Web Intel: LeakBase ULP #Free1 Drops 95,231 Stolen Passwords

HEROIC
HEROIC Threat Intelligence Team
Email Address Homepage Url Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 95,231
Source Type Database
Origin Darkweb
Password Type Plaintext

HEROIC analysts identified a stealer log release on August 4, 2024, in which the threat actor known as "moi geroi" posted a credential file labeled "ULP #Free1" on a prominent hacking forum. The log contains approximately 785,296 total records, with 95,231 unique entries. The exposed data includes email addresses, homepage URLs, and plaintext passwords collected by information-stealing malware from infected devices. This release is part of a multi-part series by the same actor -- see also: LeakBase ULP #Free by moi geroi.

Why This Is Dangerous: Plaintext passwords are immediately operational weapons. Every email-and-password pair in this log can be tested against banks, email services, and e-commerce platforms within seconds using automated tools. The accompanying homepage URLs tell attackers exactly which services each victim was actively using, enabling them to focus credential stuffing attempts where they are most likely to succeed. Combined across both releases in this series, the actor distributed nearly 190,000 unique compromised accounts.

What Was Exposed

  • Email Address
  • HomePage URL
  • Plaintext Password

Why This Matters

Stealer logs containing plaintext passwords create an immediate, multi-platform threat. Victims who reuse the same password across accounts lose access to every service where that password was used the moment attackers begin testing. Email account takeover is often the first domino to fall, since email access allows password resets on every other linked service. From there, attackers can commit financial fraud, drain accounts, sell access to other criminals, or use compromised accounts to spread phishing campaigns to the victim's contacts.

How Stealer Logs Work

Stealer logs are credential archives produced by information-stealing malware. The malware infects a victim's device -- often through phishing links, trojanized software downloads, or malicious browser extensions -- and immediately begins harvesting saved passwords from browsers, password managers, and login forms. It also records the URLs of sites the victim visits while logged in. All of this data is silently transmitted to attacker-controlled infrastructure. The assembled logs are then packaged and distributed on dark web forums as free samples to attract buyers for larger private collections.

Check If You Are Affected

If your email address is among the 95,231 unique records in this log, your password for at least one online service is exposed. Use the HEROIC free identity scanner to check whether your credentials appear in this release or any of the 400 billion+ records in our database. Change exposed passwords immediately and activate two-factor authentication on all important accounts.

Related Parts of This Breach

Breach Breakdown

Domain N/A
Leaked Data Email Address, HomePage URL, Plaintext Password
Password Types Plaintext
Date Leaked 31 Oct 2024
Check in 5 seconds

95,231 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,304 scanned today
Breach Rank #2,272 by affected users
Impact Score
4
sensitivity + scale + recency
Est. Financial Impact $689.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance