Breach Intelligence Report 18 Feb 2025

10 Million Passwords From the Telegram Alien ULP P744 Dump Leaked Online

HEROIC
HEROIC Threat Intelligence Team
Email Address Homepage Url Plaintext Password
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 10,002,004
Source Type Database
Origin Telegram
Password Type Plaintext

HEROIC analysts catalogued a stealer log distributed through a public Telegram channel on February 12, 2025, under the designation TXTLOG_ALIEN - 744. The threat actor behind it, operating as "alien," has built a pattern of releasing large-volume credential packs through messaging platforms rather than traditional dark web forums, making the data accessible to a far wider audience of would-be attackers. This specific release contained approximately 56.2 million lines of raw data, from which analysis extracted 10,002,004 unique email addresses, each accompanied by a plaintext password and a homepage URL identifying the site where the credential was captured.


Why Credentials Distributed via Telegram Are a Heightened Threat

Unlike dark web forums that require registration and vetting, Telegram channels are open to anyone with the app installed. When a threat actor publishes a 10-million-record credential dump to a public Telegram channel, every subscriber, whether a sophisticated attacker or a curious amateur, receives it instantly. The speed and reach of this distribution model means that by the time a victim learns their password was exposed, it may already have been tested against dozens of platforms. Plaintext passwords eliminate any technical barrier to misuse.


What Was Exposed in the Telegram Alien ULP P744 Dump

  • Email addresses (10,002,004 unique accounts confirmed)
  • Plaintext passwords (immediately usable for login attempts)
  • Homepage URLs (identifying the specific sites victims were logged into at time of infection)

Why This Matters for Account Security and Identity Theft

Ten million plaintext credential pairs in the hands of an unrestricted Telegram audience is a direct pipeline to credential stuffing at scale. Attackers load these email and password combinations into automated tools and test them across banking apps, e-commerce platforms, corporate VPNs, and social media. A single reused password can cascade into account takeover across multiple services. The homepage URLs narrow the attack surface further, giving attackers a prioritized list of exactly where to try each credential. Victims who use the same password for email and banking are at especially acute risk of financial fraud.


How Stealer Log Breaches Work

Stealer logs like TXTLOG_ALIEN - 744 are not created by breaching a single company. They are assembled from thousands of individual infections. Infostealer malware, often delivered through pirated software, malicious browser extensions, or phishing emails, installs silently on a victim's computer and harvests every saved password it can find. It also records which sites the browser has open and captures active session cookies. The attacker collects these harvests from infected machines across many countries, compiles them into a single file, and publishes or sells the result. The ULP format, URL:Login:Password, is the industry shorthand for this type of structured credential dump.


Check If Your Data Appears in the Alien ULP P744 Leak

HEROIC's free breach scanner indexes over 400 billion exposed records, including stealer logs distributed through Telegram channels like this one. Enter your email address to find out immediately whether your credentials were part of this dump. If they were, change the affected password everywhere you use it and enable two-factor authentication on your most sensitive accounts. Start your free scan at heroic.com.

Breach Breakdown

Domain N/A
Leaked Data Email Address, HomePage URL, Plaintext Password
Password Types Plaintext
Date Leaked 18 Feb 2025
Check in 5 seconds

10,002,004 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,218 scanned today
Breach Rank #325 by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $72.4M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance