The UHQ MIX PART 10 0930 Data Quietly Appeared on the Dark Web
HEROIC analysts identified this stealer log on May 7, 2023. The breach exposed 106,202 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as UHQ MIX PART 10 0930.
Why This Is Dangerous
The UHQ MIX PART 10 0930 stealer log surfaced quietly on the dark web with over 106,000 plaintext password entries. The UHQ label, short for ultra high quality, indicates that criminals consider these credentials to be verified and active. Working credentials fetch higher prices in underground markets and are used first in targeted attack campaigns.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs (website addresses where credentials were stolen)
Why This Matters
Over 106,000 credential pairs from this breach are ready for use in credential stuffing and account takeover attacks. When criminals label stolen data as high quality, it indicates the passwords were recently captured and are likely still valid. Affected users face risks including unauthorized access to email, financial accounts, and any service sharing the same password.
How Stealer Logs Work
Stealer malware installs silently on a victim's computer through deceptive downloads, phishing links, or malicious browser extensions. It extracts saved passwords from browsers and captures login credentials as they are typed. The data is packaged into files and distributed through private Telegram channels and dark web forums under labels like UHQ MIX to signal credential quality to buyers.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to see if your credentials appear here or elsewhere. Free, takes seconds.
Breach Breakdown
106,202 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds