The Satanic 10M ULP Part 2 Sept #9 Dump Contains Exactly 2,871,866 Stolen Email and Password Pairs
HEROIC analysts flagged this data on September 12, 2024, when a threat actor using the handle "Satanic" posted the ninth installment of a ten-part credential series to BreachForums. The dump, titled "Private Satanic 10M ULP Part 2 Sept #9," contained 2,871,866 records with email addresses, plaintext passwords, and homepage URLs. This release was part of a methodical, ongoing operation: the actor had already distributed a separate set of ten logs the week before, and this was the penultimate release in the second series. Sibling parts in this campaign are documented here: Satanic 10M ULP Part 2 Sept #10 and Satanic 10M ULP Part 2 Sept #3.
Nearly 2.9 million records containing plaintext passwords represent a severe and immediate threat. Plaintext passwords require no cracking, no rainbow tables, and no computational effort from an attacker. They can be fed directly into automated credential stuffing tools within minutes of a dump appearing online. The pairing of each password with a specific email address and a homepage URL means attackers also know the likely services each victim uses, allowing them to prioritize their attacks against the highest-value targets first.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
When attackers obtain plaintext email-and-password pairs at this scale, they run them against bank portals, streaming services, e-commerce platforms, and corporate email systems simultaneously. Password reuse rates remain high across the general population, which means a credential valid on one service is often valid on several others. Once inside an email account, an attacker can request password resets on every service associated with that address, compounding the damage significantly. Identity theft and financial fraud become straightforward follow-on steps from that point.
How Database Breaches Work
Database breaches of this type are typically the product of infostealer malware infections. A stealer program installs itself silently on a victim's device, often through a phishing link or a trojanized software download. Once active, it extracts credentials stored in browsers, password managers, and saved login sessions, then sends that data back to attacker-controlled infrastructure. Operators compile thousands of individual infections into bulk logs, which are then sold or posted freely on underground forums like BreachForums. The ULP format used here organizes each record as a URL, login, and password triplet, making the data immediately compatible with credential stuffing automation.
Check If You Are Affected
HEROIC's free breach scanner searches across more than 400 billion exposed records to tell you whether your email address appeared in this dump or any other known breach. Enter your email at heroic.com to get an immediate answer, and find out exactly what personal data has been exposed so you can change compromised passwords before an attacker uses them.
Related Parts of This Breach
- BreachForums Private Satanic 10M ULP Part 2 Sept #10 by Satanic
- BreachForums Private Satanic 10M ULP Part 2 Sept #3 by Satanic
- BreachForums Private Satanic 10M ULP Part 2 Sept #7 by Satanic
- BreachForums Private Satanic 10M ULP Part 2 Sept #5 by Satanic
- BreachForums Private Satanic 10M ULP Part 2 Sept #6 by Satanic
- BreachForums Private Satanic 10M ULP Part 2 Sept #2 by Satanic
- BreachForums Private Satanic 10M ULP Part 2 Sept #1 by Satanic
- The Satanic 10M ULP Part 2 Sept #8 Stealer Log
- The BreachForums Private Satanic 10M ULP Part 2 Sept #4 Dump
Breach Breakdown
2,871,866 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds