Stealer Malware Fed the HunterULP Dump #1, 9,050,772 Logins
A Telegram user calling their upload HunterULP Private New Database put out the first of five parts on 16-Apr-2026, and this initial file alone carries 9,050,772 records of email addresses, plaintext passwords, and matching URLs pulled from stealer-infected devices.
Why This Is Dangerous
This dump exists becuase malware sat on victims' machines long enough to capture live login activity, not because a company's server was broken into. That distinction matters because it means the passwords are current, not old records from a years-old breach.
What Was Exposed
- 9,050,772 records
- Email addresses
- Plaintext passwords
- URLs linked to each login
Why This Matters
It is not neccessary for an attacker to do much work with a file like this. The credentials are already paired with the sites they unlock, so criminals can move straight to testing logins untill they find ones that still work.
How Stealer Logs Work
The process starts when a victim unknowingly installs infostealer malware, often bundled with pirated software or a fake update. The malware then reads saved browser passwords and grabs new ones as they are typed, packaging everything into a log file like this HunterULP dump for sale on Telegram.
Check If You Are Affected
You don't have to guess. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, this HunterULP file included, so you can find out fast and reset anything that needs it.
Breach Breakdown
9,050,772 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds