VIP_ULP_Free Leak Exposed Plaintext Passwords for 144,870 Users
A third file under the VIP_ULP_Free branding, this one written with underscores instead of spaces, appeared on Telegram on 12-May-2026 with 144,870 records inside. Small formatting differences aside, the actual contents are just as sensitive as the other files carrying this name.
Why This Is Dangerous
What stands out here is one exposed detail in particular: every record includes the plaintext password sitting right next to the login URL. There's no seperate step needed to make the data usable, it's already formatted for someone to just plug in and try logging in themselves.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs for each account
- 144,870 total records exposed
Why This Matters
Attackers occassionally test leaked credentials against banking sites, email providers, and social media all at once, a method known as credential stuffing. It's definately worth remembering that even a smaller leak of under 150,000 records can still cause real damage if your specific login happens to be in the batch.
How Stealer Logs Work
This type of file is generated automatically by infostealer malware that infects a device and immediately begins copying saved browser credentials. The stolen data gets compiled into a single log and shipped off to whoever controls the malware, who then decides whether to sell it, trade it, or in this case, post it publicly on Telegram.
Check If You Are Affected
Since this leak includes both passwords and the exact URLs they unlock, checking your exposure matters more than usual. HEROIC's free breach scanner covers over 400 billion leaked records and can tell you in seconds if your email was part of the VIP_ULP_Free dump. If it was, change the password on that account right away.
Breach Breakdown
144,870 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds