Our Analysts Found the UHQ Shopping Base: 99,981 Stolen Logins
HEROIC analysts discovered a combolist marketed as 100k UHQ Shopping Base circulating in a Telegram channel in January 2023. The file actually contains 99,981 records, just under the 100,000 the name advertises, pairing email addresses with plaintext passwords and the shopping site URLs where each credential was used. Why This Is Dangerous: Because these passwords are stored in plaintext, anyone who downloads the file can log in with the exposed credentials right away. Since the URLs point to shopping sites, some of these accounts may still have saved payment methods or stored addresses attached to them. What Was Exposed: - Email addresses - Plaintext passwords - URLs for the shopping sites tied to each login Why This Matters: If a password on this list is reused anywhere else, an attacker can use it to log into other accounts, place unauthorized orders, or drain stored payment methods. Retail account takeovers like this often lead to financial fraud and identity theft, especially when saved billing details are involved. How a UHQ Combolist Like This Gets Built: UHQ stands for ultra high quality, a label sellers use to market combolists they claim have a higher rate of working logins. Criminals build these files by pulling credentials from older breaches, phishing pages, and malware logs, then sorting them by category, in this case shopping sites, before sharing or selling them on Telegram and dark web forums. The UHQ tag is a sales claim, not an independent verification. Check If You Are Affected: HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including combolists like this one. Run a scan to find out if your credentials are exposed and get clear steps to secure your accounts.
Breach Breakdown
99,981 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds