P724 Stealer Log Exposes 14 Million Accounts in a Single File
HEROIC Cybersecurity analysts recovered 14,031,227 unique accounts from the Telegram alien ULP P724 by alien stealer log, distributed on February 2, 2025. The archive, titled TXTLOG_ALIEN - 724, contained roughly 57.6 million lines of harvested URL, email, and plaintext password data pulled from infostealer infections across countless personal devices.
Why This Stealer Log Is Dangerous
A single log with more than 14 million unique accounts is larger than most of the headline corporate breaches of the last decade, yet it arrived with almost no press coverage. Each line is a clean URL, email, and plaintext password, ready to be pasted into a credential stuffing tool. Victims never signed up for a service that got breached, their own devices were the breach.
What Was Exposed in Telegram alien ULP P724 by alien
- 14,031,227 unique email addresses
- Plaintext passwords tied to each address
- Homepage URLs identifying the exact login target for each credential
- Approximately 57.6 million total lines of stealer log data
Why This Matters
When passwords leak in plaintext, they immediately fuel credential stuffing across banking, email, cloud storage, and work systems. Anyone who reused a single password is at cascading risk: one compromised account leads attackers to the next via saved logins, stored recovery addresses, and linked services. Email addresses in the log also drive targeted phishing, identity theft, and fraudulent account recovery.
How Stealer Log Chains Work
The alien distributor operates a numbered release chain, P723, P724, P725, dropping new bundles every few days on a Telegram channel. Each bundle aggregates infostealer output, typically from malware such as RedLine, Raccoon, or Lumma delivered through cracked software, fake installers, or malicious ads. The sequential naming is a sign of an active, ongoing harvesting operation rather than a single isolated leak.
Check If You Are Affected
HEROIC's DarkHive scanner indexes more than 400 billion exposed records, including the full P724 dataset. Search your email to see if your credentials appeared, rotate any reused passwords immediately, and enable multi-factor authentication on email, banking, and cloud accounts.
Breach Breakdown
14,031,227 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds