LeakBase 15Kk ULP #2: 3.97M U.S. Credentials Posted on Hacking Forum
Nearly 4 Million U.S. Email-Password Pairs Posted to a Hacking Forum in One Day
On March 28, 2024, a threat actor using the handle "firegoon" posted the second entry in a two-part credential list series on a prominent hacking forum. The file -- titled "15Kk ULP #2" -- contained approximately 15 million total records, of which nearly 3.97 million represent unique U.S. email addresses paired with plaintext passwords and the homepage URLs where those credentials were saved. Part one had been posted previously; combined, the two releases represent one of the larger credential list drops of early 2024.
LeakBase 15Kk ULP #2: Breach Summary
- Records Exposed: 3,966,024
- Data Types: Email addresses, plaintext passwords, homepage URLs
- Breach Type: ULP credential list (hacking forum)
- Country Affected: United States
- Date Leaked: March 28, 2024
What "ULP" Means and Why These Lists Are Dangerous
ULP stands for URL:Login:Password -- a structured credential list format where each row contains the website URL, the login email or username, and the password in plaintext. Unlike stealer logs (which are captured directly from infected devices), ULP lists are often aggregated from multiple sources: previous breach dumps, stealer log extracts, and previously cracked password hashes. The "15Kk" designation indicates aproximately 15,000 thousand (15 million) raw records across both parts of firegoon's series. These lists are the raw material for credential stuffing attacks -- automated tools can consume a 15-million-row ULP file and test every login against every major platform within hours.
Why a Two-Part Release Strategy Amplifies Exposure
Firegoon's choice to release in two parts -- rather than a single dump -- is common in hacking forum culture. Part one serves as proof of supply and builds anticipation. Part two delivers the volume, often to a wider audience now aware of the series. By the time LeakBase 15Kk ULP #2 hit the forum on March 28, 2024, there was allready an established audience expecting it. This staged release model maximizes attention and ensures the data reaches as many potential consumers as possible. For the 3.97 million people whose credentials appear in part two, the two-part release means their exposure was twice as publicized as a single-shot dump would have been.
Check Your Exposure in HEROIC's Free Scanner
HEROIC's free breach scanner searches across more than 400 billion exposed records, including large ULP credential lists like the LeakBase 15Kk series. Enter your email to see if your credentials appear in this or any other known breach database. With nearly 4 million U.S. records in this single release, the probabilty that a given American's credentials appear is substantialy higher than in a typical stealer log drop.
Breach Breakdown
3,966,024 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds