The ULP Good by Moon Breach Gave Hackers Access to Real Accounts
HEROIC analysts identified this Stealer log on 02-May-2025. The breach exposed 1,084,030 records, with stolen data including Email Addresses, Plaintext Passwords, and URLs. The source is identified as ULP GOOD BY MOON_SUPP1_000001, uploaded by a Telegram User.
Why This Is Dangerous
With over one million plaintext email and password pairs exposed, this stealer log represents a major credential leak. These credentials give attackers direct access to a massive number of real accounts across email platforms, banking services, social media, and more. The sheer volume makes this breach especially impactful for credential stuffing campaigns.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
A breach of this size provides attackers with a substantial pool of verified credentials to test across multiple platforms. Because the passwords are in plaintext, no additional processing is needed before use. People whose credentials appear in this log face immediate risk of account takeover, financial fraud, and identity theft.
How Stealer Logs Work
Stealer logs are generated when malware infects a victim's computer and silently records their login activity. Every time the victim types a username and password into a website, the malware captures it along with the site URL. The resulting files are packaged and distributed through Telegram channels, where cybercriminals buy, sell, and share them.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to find out if your credentials appear in this breach or others. The scan is free and takes seconds.
Breach Breakdown
1,084,030 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds