US Stealer Log Leak: ‘UHQ MIX NEW 27’ Exposes 82,972 Passwords
In April 2023, a user on Telegram uploaded a stealer log file labeled "UHQ MIX NEW 27," exposing 82,972 records tied to US-based accounts. The dump was pulled straight from malware-infected computers, so instead of a single company's servers being hacked, this is a collection of login endpoints, email addresses, and plaintext passwords siphoned directly off victims' devices and repackaged for sale and distribution on Telegram.
Why a Telegram Stealer Log Dump Is Dangerous
Unlike a typical corporate data breach, a stealer log comes from malware that ran on someone's own computer, capturing whatever was typed or saved in the browser at the time. That means the passwords in "UHQ MIX NEW 27" were stored in plaintext, not hashed or encrypted, so anyone who downloads the file can read and use them immediately. Because these logs often bundle the website URL alongside the matching email and password, criminals can log straight into an account without any guesswork.
What Was Exposed in This Stealer Log
- Email addresses
- Plaintext passwords
- URLs (the sites those credentials belong to)
Why This Matters for Anyone Affected
When an email, password, and website URL are packaged together like this, they become a ready-made toolkit for credential stuffing. Attackers feed these combinations into automated tools that test the same login across banking, email, and shopping sites, betting that the password was reused. If it was, the result can be account takeover, identity theft, or direct financial fraud, all without the victim doing anything new to trigger it.
How Stealer Log Breaches Like This One Happen
Infostealer malware typically arrives through a cracked software download, a fake update, or a malicious email attachment. Once installed, it quietly scrapes saved passwords, autofill data, and browser session details from the infected device and sends everything back to the attacker. Files like "UHQ MIX NEW 27" are the end product of that process, compiled logs uploaded to Telegram channels where other criminals buy, trade, or use them directly.
Check If You Are Affected
If you reused a password across multiple sites, a single exposed login can put every one of those accounts at risk. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including stealer logs like this one, so you can find out in seconds if your information was exposed and take action before someone else does.
Breach Breakdown
82,972 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds