Quietly Massive: UP_KURZL0G Database Leaks 27.2M Records
HEROIC analysts quietly flagged a stealer log database, labeled "PREMIUM NEW UNRAPPED DATABASE UP_KURZL0G," uploaded to a Telegram channel on October 14, 2025. What looks like a routine file listing turns out to hold 27,248,952 records of email addresses, plaintext passwords, and the URLs each login was captured from.
Why This Is Dangerous
A number this large is easy to scroll past, but it represents tens of millions of real people whose saved logins are now sitting in plaintext, ready to use. Because each password is matched to the exact site it unlocks, there is no cracking required. Attackers can simply open the file and start logging in.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each login
Why This Matters
At this scale, the leak becomes fuel for automated credential stuffing tools that quietly test millions of logins against banking, retail, and email sites around the clock. Reused passwords let a single record trigger account takeover, identity theft, and financial fraud across accounts the victim never expected to be at risk.
How Stealer Logs Work
A database this size is usually built by combining many smaller stealer logs collected from malware infections over time. Each infected device quietly hands over saved browser passwords and login pages, and these individual logs get merged, labeled "premium," and marketed as a single large package on Telegram and dark web forums.
Check If You Are Affected
With tens of millions of records involved, the odds of being included are not small. HEROIC's free breach scanner checks your email against over 400 billion leaked records, giving you a quiet, quick answer before this data causes a problem.
Breach Breakdown
27,248,952 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds