Change Your Passwords Now: Telegram ULP P770 Leaked 12.1M Logins
HEROIC found 12,111,667 records in Telegram alien ULP P770 by alien on 25-Feb-2025, exposing email addresses, HomePage URLs, and plaintext passwords pulled from a 54.9 million line infostealer log.
Why This Telegram alien ULP P770 Dump Is Dangerous Right Now
Speed is the whole story here. The file titled TXTLOG_ALIEN - 770 was pushed through a public Telegram channel on February 25, 2025, and within hours it was mirrored across credential stuffing tools. Anyone sitting in that channel could download 54.9 million lines of raw data and start brute forcing online accounts before the affected users even read the news. Of those lines, 12,111,667 are clean, deduplicated, and paired with the exact URL they belong to.
If you have not rotated passwords on major accounts in the last few months, you are the target. The longer the delay between a stealer log leak and a password change, the higher the chance an attacker gets in first.
What Was Exposed in Telegram alien ULP P770 by alien
- 12,111,667 unique records extracted from a 54.9 million line log
- Email addresses used as account logins across thousands of services
- Plaintext passwords captured from victim browsers by infostealer malware
- HomePage URLs showing attackers exactly which site each credential unlocks
- Distributed through the alien ULP P770 channel by the handle alien, a known stealer log operator
Why This Matters
A 12 million record ULP dump is large enough to move the baseline risk of every reused password on the internet. Credential stuffing bots do not check the name of the dump, they only check whether your email and password combination works. If you have reused even one password from the last few years, it is likely already being tested against banking, email, and crypto exchange logins.
The HomePage URL column makes the damage targeted rather than random. Instead of spraying credentials everywhere, attackers can sort by site name, pull only the rows that hit high value platforms, and attack those accounts first. That workflow takes a single script and a few hours.
How Telegram Stealer Log Drops Work
Criminal operators like alien run Telegram channels that deliver fresh ULP files on a schedule, sometimes daily. The logs come from commodity infostealer malware such as RedLine, Lumma, and StealC that runs on victim PCs after a malicious download. The stealer exfiltrates browser saved passwords, cookies, and autofill to a command server. Operators repackage the output into numbered drops like P770, P771, P772, and release them for free or for sale.
Because the same malware keeps running, new drops appear constantly. A password you changed last year can show up in a dump next week if a device was still infected.
Check If You Are Affected
HEROIC continuously ingests Telegram stealer log drops like alien ULP P770 into a monitoring system that covers 400 billion compromised records. A single free scan against that index tells you whether your email, password, or accounts tied to specific URLs appear in this dump or any of the surrounding alien series leaks. Run a HEROIC scan now and rotate anything that comes back hot.
Breach Breakdown
12,111,667 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds