10 Million Passwords From the Telegram Alien ULP P744 Dump Leaked Online
HEROIC analysts catalogued a stealer log distributed through a public Telegram channel on February 12, 2025, under the designation TXTLOG_ALIEN - 744. The threat actor behind it, operating as "alien," has built a pattern of releasing large-volume credential packs through messaging platforms rather than traditional dark web forums, making the data accessible to a far wider audience of would-be attackers. This specific release contained approximately 56.2 million lines of raw data, from which analysis extracted 10,002,004 unique email addresses, each accompanied by a plaintext password and a homepage URL identifying the site where the credential was captured.
Why Credentials Distributed via Telegram Are a Heightened Threat
Unlike dark web forums that require registration and vetting, Telegram channels are open to anyone with the app installed. When a threat actor publishes a 10-million-record credential dump to a public Telegram channel, every subscriber, whether a sophisticated attacker or a curious amateur, receives it instantly. The speed and reach of this distribution model means that by the time a victim learns their password was exposed, it may already have been tested against dozens of platforms. Plaintext passwords eliminate any technical barrier to misuse.
What Was Exposed in the Telegram Alien ULP P744 Dump
- Email addresses (10,002,004 unique accounts confirmed)
- Plaintext passwords (immediately usable for login attempts)
- Homepage URLs (identifying the specific sites victims were logged into at time of infection)
Why This Matters for Account Security and Identity Theft
Ten million plaintext credential pairs in the hands of an unrestricted Telegram audience is a direct pipeline to credential stuffing at scale. Attackers load these email and password combinations into automated tools and test them across banking apps, e-commerce platforms, corporate VPNs, and social media. A single reused password can cascade into account takeover across multiple services. The homepage URLs narrow the attack surface further, giving attackers a prioritized list of exactly where to try each credential. Victims who use the same password for email and banking are at especially acute risk of financial fraud.
How Stealer Log Breaches Work
Stealer logs like TXTLOG_ALIEN - 744 are not created by breaching a single company. They are assembled from thousands of individual infections. Infostealer malware, often delivered through pirated software, malicious browser extensions, or phishing emails, installs silently on a victim's computer and harvests every saved password it can find. It also records which sites the browser has open and captures active session cookies. The attacker collects these harvests from infected machines across many countries, compiles them into a single file, and publishes or sells the result. The ULP format, URL:Login:Password, is the industry shorthand for this type of structured credential dump.
Check If Your Data Appears in the Alien ULP P744 Leak
HEROIC's free breach scanner indexes over 400 billion exposed records, including stealer logs distributed through Telegram channels like this one. Enter your email address to find out immediately whether your credentials were part of this dump. If they were, change the affected password everywhere you use it and enable two-factor authentication on your most sensitive accounts. Start your free scan at heroic.com.
Breach Breakdown
10,002,004 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds