Breach Intelligence Report 13 Jul 2026

How Malware Led to 102K Stolen Logins in the UHQ Shopping Dump

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs 102k UHQ Shopping Combolist 2 uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 102,561
Source Type Stealer log
Origin United States
Password Type plaintext

In December 2022, a file labeled 102k UHQ Shopping Combolist 2 surfaced on a Telegram channel, and HEROIC analysts have since confirmed its contents. The dataset holds 102,561 records extracted from infected devices, each containing an email address, a plaintext password, and the URL of the shopping site where those credentials were used.

The name tells part of the story: UHQ stands for "Ultra High Quality," a term traffickers use to signal that the credentials have been verified as working. This is not a raw, unfiltered dump. It is a curated list designed for immediate exploitation against online retail platforms.


Why Plaintext Passwords Remove Every Safety Net

Every password in this combolist appears in plaintext, meaning there is no cryptographic barrier between an attacker and your account. Unlike hashed or encrypted credentials that require computational effort to decode, plaintext entries can be copied directly into a login form.

For shopping accounts specifically, the stakes are high. Saved payment methods, stored shipping addresses, order histories, and loyalty point balances are all accessible once an attacker logs in. Many retail sites do not require re-authentication for purchases under a certain threshold, making unauthorized transactions trivially easy.

The plaintext format also means these credentials can be loaded into automated attack tools without any preprocessing, allowing attackers to test them across thousands of sites in a matter of hours.


What Was Exposed in the UHQ Shopping Combolist 2 Dump

  • Email Addresses — The login identifiers for shopping accounts across multiple retail platforms, also usable for phishing and social engineering campaigns.
  • Plaintext Passwords — Fully readable passwords captured by infostealer malware from browsers and password managers on compromised devices.
  • URLs — Direct links to the login pages of the shopping sites where these credentials were entered, giving attackers a ready-made target list.

Why 102,561 Shopping Credentials Create a Ripple Effect

A dataset of this size does not exist in isolation. Credential stuffing operations aggregate multiple combolists into massive libraries, and a verified shopping-focused list is particularly valuable. Attackers know that people who shop online frequently reuse the same email and password across their retail accounts, banking portals, and even corporate logins.

Research consistently demonstrates that password reuse rates remain alarmingly high. When 102,561 credentials from shopping sites enter circulation, the real exposure extends far beyond retail. Each working pair becomes a key that may unlock email inboxes, cloud storage, financial services, and social media profiles.

Because this list was marketed as UHQ, the hit rate for credential stuffing is expected to be significantly higher than average, making it a preferred resource for automated account takeover operations.


How Stealer Logs Built This Shopping Credential List

Infostealer malware is the engine behind combolists like this one. These programs infect devices through phishing emails, pirated software downloads, and malicious browser extensions. Once installed, the malware silently records every credential entered into web browsers, capturing the URL, username, and password in real time.

The stolen data is packaged into structured log files and exfiltrated to command-and-control servers. From there, operators sort the credentials by category — banking, shopping, streaming, social media — and compile them into themed combolists for sale or free distribution on Telegram.

The UHQ Shopping Combolist 2 represents the output of this pipeline: credentials harvested from potentially thousands of infected devices, filtered to include only shopping-related logins, verified for validity, and then uploaded for mass consumption.


Check If Your Credentials Appear in This Leak

With over 102,000 records in this single combolist alone, the chances of exposure are meaningful for anyone who shops online. If you have ever saved login credentials in your browser or used the same password across multiple shopping sites, your accounts may be at risk.

HEROIC provides a free breach scanner that searches more than 400 billion records from known breaches and stealer log compilations. A quick scan of your email address can reveal whether your credentials appear in this dataset or any of the thousands of others indexed in the system.

If you find a match, take action immediately: change the compromised password everywhere it was used, enable multi-factor authentication on all accounts that support it, and review recent account activity for signs of unauthorized access.

Breach Breakdown

Domain 102k UHQ Shopping Combolist 2 uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 13 Jul 2026
Check in 5 seconds

102,561 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,261 scanned today
Breach Rank #N/A by affected users
Impact Score
4
sensitivity + scale + recency
Est. Financial Impact $742.1K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance