Months After Leaking, HunterULP Dump #2’s 11.9M Logins Linger
It has been more than two months since the second HunterULP Private Database dump first surfaced on Telegram on 16-Apr-2026, and its 11,961,918 records of emails, plaintext passwords, and URLs are still circulating today.
Why This Is Dangerous
Time works against victims here. The longer a stealer log dump sits out there, the more copies get made and the more chances criminals have had to test the logins inside. A leak that is months old isn't old news, it is definately still a live threat.
What Was Exposed
- 11,961,918 records
- Email addresses
- Plaintext passwords
- URLs matched to each login
Why This Matters
Anyone who hasn't changed their passwords since April is still exposed today. Attackers don't need to act imediately after a leak drops, they can wait weeks or months, betting that victims will assume the danger has passed.
How Stealer Logs Work
This dump was never publically announced, it simply appeared on a Telegram channel the way most stealer logs do. Malware on infected devices quietly collected saved browser passwords over time, and once enough data piled up, the file was packaged and shared.
Check If You Are Affected
Even if this leak happened months ago, it's not too late to check. HEROIC's free breach scanner searches more than 400 billion leaked records, including this HunterULP dump, so you can finally see if your information is part of it.
Breach Breakdown
11,961,918 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds