2.4 Million Passwords From ULP BY MOON_000005 Just Leaked
HEROIC analysts identified a massive stealer log dataset named "ULP BY MOON_000005," uploaded to a Telegram channel on April 30, 2025. Unlike the smaller logs typically seen from individual infections, this file contains 2,468,093 records combining email addresses, plaintext passwords, and the exact URLs of the websites those credentials belong to, making it one of the larger stealer log dumps HEROIC has tracked from this source.
Why This Is Dangerous
The name "ULP" refers to the format itself: URL, Login, Password, listed together in a single line for each stolen account. That format is exactly what makes stealer logs so dangerous. There's no password hash to crack and no guesswork involved. An attacker can open the file, pick a target website, and immediately try the matching plaintext password against the matching login. With 2.4 million entries, this single file gives criminals a ready-made list of working logins across an enormous number of websites and services.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the sites the credentials were used on
Why This Matters
At this scale, the risk isn't limited to one website. Because passwords are stored in plaintext and matched to specific login pages, attackers can walk through the file and attempt account takeover on banking sites, email providers, and social media platforms wherever the same credentials were reused. A dataset this size also makes automated credential stuffing far more efficient, since bots can test millions of email and password pairs against popular sites in a short amount of time.
How Stealer Logs Work
Stealer logs are produced by infostealer malware that infects a device, often through pirated software, malicious ads, or phishing emails, and then silently harvests every saved password, autofill entry, and active browser session it can find. Individual infections typically produce small logs, but criminals frequently combine thousands of these logs into one large file, exactly what happened with "ULP BY MOON_000005." Combined files like this are then shared or sold in bulk on platforms like Telegram, giving buyers instant access to millions of credential pairs at once.
Check If You Are Affected
With over 2.4 million accounts caught up in this single leak, the odds that your email is among them are worth checking. HEROIC's free breach scanner searches a database of more than 400 billion exposed records to tell you instantly whether your information has surfaced, along with steps to secure your accounts if it has.
Breach Breakdown
2,468,093 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds