One Forum. Ten Numbered Batches. The Satanic 10M ULP Sept #5 Dump Exposed 3.1 Million Plaintext Credentials.
One forum post. Five numbered batches already behind it. HEROIC analysts flagged the BreachForums Private Satanic 10M ULP Sept #5 by Satanic dataset on September 4, 2024, as the fifth installment in a systematic credential dump campaign run by the same threat actor. This release alone contained 3,182,474 records, each pairing an email address with a plaintext password and a homepage URL. The scale and the recurring pattern of releases signal a coordinated, ongoing operation rather than a one-off incident. Other parts of this campaign documented by HEROIC include BreachForums Private Satanic 16M ULP by Satanic, BreachForums Private Satanic 10M ULP Sept #6 by Satanic, and BreachForums Private Satanic 10M ULP Sept #7 by Satanic.
Three million plaintext passwords sitting in a freely downloadable file is a significant threat. Because these credentials require no decryption or processing, they can be loaded directly into automated tools and tested against live services. Each of the 3.1 million records also includes a homepage URL, which tells attackers exactly which website the victim was using when the credential was captured. That context removes guesswork and dramatically speeds up targeted account takeover attempts.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
When plaintext passwords are paired with email addresses and service URLs, attackers have everything needed to attempt immediate account access. Credential stuffing attacks automate this process, running millions of login attempts across banking, retail, email, and social media platforms in hours. Password reuse makes the problem exponential: one compromised credential on a low-security site can open the door to a victim's primary email, which in turn enables password resets across every other account. The fifth release in this series arriving on the same day as the others indicates the threat actor had a large, pre-compiled dataset ready to distribute at scale.
How Database Breaches Work
Stealer log compilations like this one are assembled from malware that silently runs on infected devices. The malware, often distributed through phishing emails or compromised software downloads, scans the victim's system for saved credentials in browsers, password managers, and desktop applications. It captures usernames, passwords, and the URLs associated with each credential, then sends the data to the attacker's server. These logs are later cleaned, deduplicated, and sorted into batches before being posted to forums like BreachForums. Each numbered release in the Satanic series represents one such batch, which is why the data types are identical across all parts: they all originate from the same underlying malware operation.
Check If You Are Affected
HEROIC's free breach scanner checks your email address and credentials against more than 400 billion records, including this dataset and every other known release from the Satanic ULP series. If your data appears in the Sept #5 dump or any related batch, change your passwords immediately, prioritize the accounts linked to the homepage URLs in the data, and enable two-factor authentication wherever possible. Use HEROIC's scanner now to check your exposure.
Related Parts of This Breach
Breach Breakdown
3,182,474 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds