The 1.6KK Mix Ultra Base Data Just Went Public on the Dark Web
HEROIC analysts identified this stealer log on April 2, 2023. The breach exposed 1,531,764 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as 1.6KK Mix Ultra Base.
Why This Is Dangerous
This breach contains plaintext passwords, meaning the passwords are stored and exposed exactly as users typed them. There is no encryption protecting these credentials. Anyone with access to this file can immediately use the usernames and passwords to attempt logins on other websites and services.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs (website addresses where credentials were stolen)
Why This Matters
With 1,531,764 exposed email and password pairs, this breach gives criminals a large pool of working credentials to exploit. Attackers use these lists to attempt logins on banking sites, email accounts, social media platforms, and online stores. If a victim reuses the same password across multiple sites, a single stolen credential can open access to many accounts at once.
How Stealer Logs Work
Stealer logs are created by malware that secretly installs on a victim's computer. Once installed, the malware records keystrokes, captures saved browser passwords, and collects login credentials as users visit websites. This data is then sent to a remote server controlled by the attacker. The collected credentials are packaged into files and shared or sold on dark web forums and private Telegram channels.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to see if your credentials appear here or elsewhere. Free, takes seconds.
Breach Breakdown
1,531,764 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds