The UHQ MIX Dump: 99,858 Stolen Login Credentials Hit the Dark Web
HEROIC analysts traced a combolist named "UHQ MIX PART 1 1115" to a Telegram upload from January 2023. "UHQ" is shorthand criminals use for "ultra high quality," and the file lives up to that marketing with 99,858 records pairing email addresses, plaintext passwords, and associated URLs.
Why the UHQ MIX Leak Is Dangerous
The "UHQ" label typically signals that a combolist has already been filtered and verified for working logins, which is exactly what makes it dangerous. With nearly 100,000 pre-checked credential pairs in one file, attackers can run large-scale automated login attempts with a higher expected success rate than an unverified dump.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs
Why This Matters
Even though this dump surfaced years ago, credentials from lists like this continue to circulate and get reused in new attacks, since so many people never change a password once it has been set. If a credential from this file was still valid at any point, it could have enabled credential stuffing, account takeover, or fraud long after the original upload date.
How a "Mixed" Combolist Like This Is Built
A "mix" combolist combines credentials from multiple sources, various older breaches and stealer logs, into a single unsorted file rather than focusing on one company or domain. Criminals favor mixed lists like "UHQ MIX PART 1 1115" because they cast a wide net across many websites and services at once.
Check If You Are Affected
Old leaks are still worth checking, since reused passwords keep old data dangerous. HEROIC's free breach scanner searches over 400 billion leaked records, including combolists like this one, so you can find out in seconds whether your email address has ever been exposed.
Breach Breakdown
99,858 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds