US Users Targeted: LeakBase 1M ULP Stealer Log by TheKuntess
HEROIC analysts found a stealer log identified as "1M ULP" and posted on LeakBase on July 4, 2024, by the threat actor known as TheKuntess. The dataset exposed 523,924 unique email addresses alongside plaintext passwords and homepage URLs. This release was the first in a confirmed series of three posts from the same actor, making it part of a coordinated credential distribution campaign. The third release in this series is documented separately: LeakBase 1M ULP 3 by TheKuntess.
Why This Is Dangerous
The United States is one of the most heavily targeted nations in credential theft operations, and logs distributed on platforms such as LeakBase quickly circulate to criminal marketplaces worldwide. Plaintext passwords in this dataset require no cracking or decryption before use. Within minutes of a log going public, automated bots begin testing the exposed email-password pairs against high-value targets including financial institutions, healthcare portals, and e-commerce platforms operating in the US market. The series nature of these releases amplifies the risk, as the combined scope of all three parts represents a substantial pool of usable credentials.
What Was Exposed
- Email Address
- Plaintext Password
- HomePage URL
Why This Matters
Credential stuffing attacks fueled by plaintext password dumps directly enable account takeover at scale. Once an attacker has a working email-password pair, they can access banking, retail, healthcare, and social media accounts, committing fraud, harvesting stored payment data, and staging further attacks against employers or associates. Identity theft originating from such logs is a documented and growing threat, with US consumers facing some of the highest rates of account-based financial fraud globally. The series pattern observed in TheKuntess releases suggests an actor systematically distributing a larger stolen dataset in installments, extending exposure over time.
How Database Breaches Work
Stealer logs are compiled from infostealer malware infections on end-user devices. The malware silently harvests credentials stored in browsers and applications, capturing the email address, password, and associated website URL for each saved login. These records are transmitted to attacker infrastructure, aggregated into bulk files, and subsequently sold or posted publicly on forums and leak sites such as LeakBase. Unlike a breach of a single company's database, stealer logs draw from thousands of compromised devices across many different websites, making the exposure highly diverse and difficult to attribute to any one organization.
Check If You Are Affected
HEROIC offers a free dark web scanner that checks your email address against more than 400 billion compromised records, including stealer log data from US-targeted campaigns like this one. If your email appears in this dataset, change all passwords where you have used the same credentials, activate two-factor authentication on every important account, and monitor your financial accounts and credit report for unauthorized activity.
Related Parts of This Breach
This leak is part of a three-part series posted by the same threat actor on LeakBase on July 4, 2024. The following related release has been documented:
Breach Breakdown
523,924 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds