How Malware Led to 102K Stolen Logins in the UHQ Shopping Dump
In December 2022, a file labeled 102k UHQ Shopping Combolist 2 surfaced on a Telegram channel, and HEROIC analysts have since confirmed its contents. The dataset holds 102,561 records extracted from infected devices, each containing an email address, a plaintext password, and the URL of the shopping site where those credentials were used.
The name tells part of the story: UHQ stands for "Ultra High Quality," a term traffickers use to signal that the credentials have been verified as working. This is not a raw, unfiltered dump. It is a curated list designed for immediate exploitation against online retail platforms.
Why Plaintext Passwords Remove Every Safety Net
Every password in this combolist appears in plaintext, meaning there is no cryptographic barrier between an attacker and your account. Unlike hashed or encrypted credentials that require computational effort to decode, plaintext entries can be copied directly into a login form.
For shopping accounts specifically, the stakes are high. Saved payment methods, stored shipping addresses, order histories, and loyalty point balances are all accessible once an attacker logs in. Many retail sites do not require re-authentication for purchases under a certain threshold, making unauthorized transactions trivially easy.
The plaintext format also means these credentials can be loaded into automated attack tools without any preprocessing, allowing attackers to test them across thousands of sites in a matter of hours.
What Was Exposed in the UHQ Shopping Combolist 2 Dump
- Email Addresses — The login identifiers for shopping accounts across multiple retail platforms, also usable for phishing and social engineering campaigns.
- Plaintext Passwords — Fully readable passwords captured by infostealer malware from browsers and password managers on compromised devices.
- URLs — Direct links to the login pages of the shopping sites where these credentials were entered, giving attackers a ready-made target list.
Why 102,561 Shopping Credentials Create a Ripple Effect
A dataset of this size does not exist in isolation. Credential stuffing operations aggregate multiple combolists into massive libraries, and a verified shopping-focused list is particularly valuable. Attackers know that people who shop online frequently reuse the same email and password across their retail accounts, banking portals, and even corporate logins.
Research consistently demonstrates that password reuse rates remain alarmingly high. When 102,561 credentials from shopping sites enter circulation, the real exposure extends far beyond retail. Each working pair becomes a key that may unlock email inboxes, cloud storage, financial services, and social media profiles.
Because this list was marketed as UHQ, the hit rate for credential stuffing is expected to be significantly higher than average, making it a preferred resource for automated account takeover operations.
How Stealer Logs Built This Shopping Credential List
Infostealer malware is the engine behind combolists like this one. These programs infect devices through phishing emails, pirated software downloads, and malicious browser extensions. Once installed, the malware silently records every credential entered into web browsers, capturing the URL, username, and password in real time.
The stolen data is packaged into structured log files and exfiltrated to command-and-control servers. From there, operators sort the credentials by category — banking, shopping, streaming, social media — and compile them into themed combolists for sale or free distribution on Telegram.
The UHQ Shopping Combolist 2 represents the output of this pipeline: credentials harvested from potentially thousands of infected devices, filtered to include only shopping-related logins, verified for validity, and then uploaded for mass consumption.
Check If Your Credentials Appear in This Leak
With over 102,000 records in this single combolist alone, the chances of exposure are meaningful for anyone who shops online. If you have ever saved login credentials in your browser or used the same password across multiple shopping sites, your accounts may be at risk.
HEROIC provides a free breach scanner that searches more than 400 billion records from known breaches and stealer log compilations. A quick scan of your email address can reveal whether your credentials appear in this dataset or any of the thousands of others indexed in the system.
If you find a match, take action immediately: change the compromised password everywhere it was used, enable multi-factor authentication on all accounts that support it, and review recent account activity for signs of unauthorized access.
Breach Breakdown
102,561 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds