Threat Actor DRAGON_ULP Leaks 1.9 Million Private Logins
In June 2026, researchers at HEROIC observed a threat actor operating under the handle DRAGON_ULP list a new file titled "PRIVATE ULP BY DRAGON_ULP 11" on a Telegram channel. The seller's eleventh release contained 1,923,996 records, each one combining an email address, a plaintext password, and a linked URL.
Why a "Private" Listing From DRAGON_ULP Raises the Stakes
Unlike free public dumps, this file was marketed as private, meaning it was sold rather than given away. Buyers who pay for private logs are usually more serious about using them quickly, since they have already invested money expecting the credentials to still work.
DRAGON_ULP appears to be a repeat seller, with this being the eleventh numbered release under the same brand name, suggesting an ongoing operation rather than a one time leak.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to the compromised logins
Why This Matters for Anyone in the Dataset
Because buyers paid for this data, they have strong motivation to act fast. Automated tools can take nearly 2 million email and password pairs and test them against banking sites, retailers, and email providers in a process known as credential stuffing.
Victims caught up in a private sale like this often see account takeover and identity theft happen sooner than with free, widely shared logs, simply because fewer people are racing to use the same stolen data.
How Private Stealer Log Operations Like DRAGON_ULP Work
Sellers who build a recognizable brand, like DRAGON_ULP, tend to run a steady pipeline. Infostealer malware infects victim devices, quietly copying saved browser passwords and autofill data back to the operator.
Rather than post everything publicly, the seller packages fresh batches and seperates them into numbered private releases, charging buyers directly instead of giving the data away for free. This keeps the seller's reputaion strong among repeat customers looking for reliable, working credentials.
Check If You Are Affected
You do not need to guess whether your information appeared in this release or any other breach tracked on the dark web. HEROIC's free scanner checks your email against a database of more than 400 billion leaked records in seconds.
If you find a match, changing that password right away is the fastest way to make sure a paid buyer never gets the chance to use it.
Breach Breakdown
1,923,996 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds