User Pass Part 4 Leak Means 1,180,511 Accounts Are at Risk
HEROIC's breach intelligence systems identified a large-scale stealer log collection called User Pass Part 4 being distributed on Telegram. This file is part of a multi-volume series and contains 1,180,511 individual credential records. Each record includes an email address, a plaintext password, and the URL of the website where the credentials were harvested by malware. The sheer volume of this dump makes it one of the more significant stealer log releases tracked by HEROIC.
Over a Million Passwords in Plaintext
All 1,180,511 passwords in this dump are stored without any form of encryption. They are fully readable, meaning attackers can use them immediately without running cracking software or rainbow table attacks. When a breach of this magnitude exposes plaintext credentials, the scale of potential damage is enormous. Each password represents a real person's account that can be accessed within seconds.
What Was Exposed
- Email Addresses — over a million unique identifiers spanning personal and corporate accounts
- Plaintext Passwords — raw, unprotected credentials that require no processing to exploit
- URLs — website addresses revealing exactly which services each password unlocks
Mass Credential Stuffing at Scale
A dataset of 1,180,511 credential pairs is a goldmine for credential stuffing operations. Automated attack tools can process this entire list in hours, testing every email-password combination against major platforms including Gmail, Amazon, PayPal, Netflix, and corporate VPN portals. Given typical password reuse rates, tens of thousands of additional accounts beyond those directly listed could be compromised through this single dump.
Stealer Logs: A Growing Threat Vector
User Pass Part 4 is the product of widespread infostealer infections across thousands of individual devices. Each entry in the log represents a separate victim whose computer was compromised by malware. Infostealers spread through cracked software, malicious browser extensions, phishing emails, and fake updates. They silently extract every password stored in the victim's browser, along with cookies, autofill data, and cryptocurrency wallet keys. The aggregated data is then compiled into numbered volumes like this one and traded on underground channels.
Check If Your Credentials Were Exposed
All 1,180,511 records from User Pass Part 4 have been indexed in HEROIC's breach database, which now contains more than 400 billion compromised credentials. Use HEROIC's free breach scanner to check whether your email address or password appears in this dump. With over a million records in play, taking immediate action to secure your accounts is critical.
Breach Breakdown
1,180,511 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds