Someone Has Your Password: 99,835 UHQ Credentials Leaked
HEROIC discovered a large, high-quality combolist labeled 100k Userpass UHQ Combo being distributed freely on Telegram. Dated February 2023, this dataset contains 99,835 records of email addresses, plaintext passwords, and the associated URLs where these credentials were captured. The "UHQ" (Ultra High Quality) label indicates these credentials have been verified or curated for higher success rates in attacks.
Plaintext Passwords in a Curated Combolist
What makes this dump particularly dangerous is the combination of plaintext passwords with UHQ curation. All 99,835 passwords are stored in readable plaintext, and the collection has been filtered for quality—meaning dead accounts and invalid credentials have likely been removed. This gives attackers a refined list of active, working login credentials that require no cracking and have a higher probability of success when used in attacks.
What Was Exposed
- Email Addresses — verified account identifiers spanning multiple online services
- Plaintext Passwords — unencrypted, curated credentials with high validity rates
- URLs — the specific services and login pages tied to each credential pair
UHQ Combos Fuel Precision Credential Stuffing
Standard credential dumps contain many inactive or misspelled entries, but UHQ lists are pre-filtered for accuracy. This makes credential stuffing attacks dramatically more efficient. With 99,835 high-confidence email-password pairs, attackers can achieve higher hit rates when testing these combinations against banking platforms, cloud services, email providers, and corporate portals. If you reuse passwords, a curated list like this represents one of the most direct threats to your account security.
From Infected Devices to Curated Combos
UHQ combolists begin as raw stealer log data harvested by infostealer malware like RedLine, Vidar, or Aurora. The malware silently captures saved passwords, cookies, and autofill data from infected devices. Cybercriminals then aggregate thousands of individual log files, deduplicate the entries, test them against live services to confirm validity, and package the working credentials into premium "UHQ" collections. These refined datasets command higher prices on underground markets and attract more sophisticated threat actors.
Check If Your Credentials Were Exposed
HEROIC's breach intelligence database encompasses over 400 billion records from data breaches, stealer logs, and dark web monitoring. Use HEROIC's free breach scanner to check if your email or credentials appear in the 100k Userpass UHQ Combo dump or any other known leak. If your information is found, change the compromised password immediately, replace it with a unique password for each service, and enable two-factor authentication to secure your accounts against future attacks.
Breach Breakdown
99,835 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds