Alien ULP P673 Leaked More Credentials Than New York City Has Residents
HEROIC analysts tracked the Telegram alien ULP P673 dataset back to January 8, 2025, when the threat actor known as "alien" distributed the stealer log through a public Telegram channel. The file contained approximately 44.2 million total lines of data. After deduplication, analysts confirmed 9,830,899 unique email addresses, each paired with a plaintext password and the homepage URL of the site where the credential was used. The sheer scale puts this dataset on par with the entire population of New York City, meaning that nearly 10 million real people have credentials that are now freely available to anyone who wants them.
Why Credentials Distributed on Telegram Are an Immediate Threat
When stolen credential sets are sold on private dark web markets, access is at least limited by cost. When they are broadcast to a public Telegram channel, the barrier drops to zero. Anyone with the app can download the data instantly. This makes the Telegram alien ULP P673 leak especially dangerous because the window between distribution and exploitation is extremely short. Attackers do not need technical skills or money to start testing these credentials against live accounts. Automated tools handle the rest in minutes.
What Was Exposed in the Telegram Alien ULP P673 Leak
- Email addresses (9,830,899 unique accounts confirmed)
- Plaintext passwords ready to use without any cracking
- Homepage URLs identifying the exact site each credential was stolen from
Why This Matters for Account Security and Identity
A plaintext email and password combination is a direct key to an account. Attackers use credential stuffing tools to test each pair across dozens of platforms automatically, targeting banking apps, email providers, cloud storage, and workplace tools. If you used the same password on multiple sites, one compromised credential can cascade into many account takeovers. Once an attacker controls your email account, they can reset passwords on every linked service, effectively locking you out while they drain accounts or impersonate you. The homepage URLs in this leak make the process even faster because attackers already know where each credential works.
How Stealer Logs Like Alien ULP P673 Are Built
Stealer logs are the output of infostealer malware. This software infects individual computers through phishing links, cracked software downloads, malicious browser extensions, or fake software updates. Once active on a device, the malware silently captures passwords as they are typed or autofilled, records which websites they belong to, and bundles everything into a structured log file that is sent back to the attacker. The "alien" actor compiled thousands of these individual logs into a single large dataset and distributed it via Telegram. Because the malware operates at the device level, this breach affects users across many different websites and services simultaneously.
Check If You Were Caught in the Alien ULP P673 Dump
HEROIC's free breach scanner covers more than 400 billion records, including stealer log collections like the Telegram alien ULP P673 dataset. Run your email address through the scanner at HEROIC.com to find out instantly whether your credentials appear in this leak or any other known breach. If they do, change the affected passwords immediately and enable two-factor authentication wherever it is available.
Breach Breakdown
9,830,899 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds