Search Your Email: The Xavier_Group Dump Exposed 191K Accounts
HEROIC analysts identified this stealer log upload in January 2026, tracking Telegram channels operated by Xavier_Group, an ongoing credential distribution network active in the infostealer underground. The file, labeled "Xavier_Ulp - 399100," contained 191,479 records after deduplication. Each record pairs an email address with a plaintext password and the URL of the website where those credentials were harvested from an infected device. The upload represents the latest in a series of ULP-format batches distributed by Xavier_Group over several months, with this particular file dated January 20, 2026.
Why the Xavier_Group January 20 Upload Is Worth Checking Against Your Email
Stealer log uploads are different from most data breaches because they do not come from one hacked company. They come from thousands of individual infected devices, meaning the email addresses in this file span every kind of website and service imaginable: banking apps, email providers, streaming platforms, government portals, health insurance sites, and everything in between. With 191,479 records spread across that many different URLs, the chances that a specific email address appears in this file, or in one of the many combolists this file will eventually be absorbed into, are significant. A free search takes ten seconds and tells you exactly whether your credentials are in the database.
What the Xavier_Ulp 399100 Upload Exposed
Each of the 191,479 records in this stealer log contains three fields extracted from compromised devices:
- Email addresses used as login identifiers across web accounts
- Plaintext passwords captured by infostealer malware before any browser-side encryption could protect them
- URLs identifying the exact website where each credential pair was active and stolen
The "399100" in the filename reflects the raw line count of the original file before deduplication reduced it to 191,479 unique records. The gap between those two numbers represents duplicate entries, a common feature in stealer logs compiled from multiple infection campaigns targeting the same users across different time periods.
Why This Matters for Account Takeover and Financial Fraud
The Xavier_Group January 20 upload creates immediate and long-term risk for the people in it. Here is how the risk unfolds:
- Automated credential stuffing tools begin testing the email and password pairs against their target URLs within hours of the file being acquired by a threat actor.
- Successful logins are used directly for account takeover: draining stored payment methods, initiating password resets on linked services, or selling account access on dark web markets.
- Even if a specific URL in the log is low-value, the attacker will test the same email and password against high-value targets like Gmail, Outlook, PayPal, and major banks, betting on password reuse.
- Longer term, the data feeds identity theft operations where stolen credentails are combined with information from other breaches to build complete profiles for fraudulent loan applications and new account fraud.
How Xavier_Group ULP Stealer Logs Are Produced
The ULP format used by Xavier_Group is an industry-standard output from infostealer malware campaigns. ULP stands for URL, Login, and Password, and describes the three-field structure of each record. The production pipeline for these files is consistent:
- Infostealer malware reaches victims through pirated software, cracked games, fake productivity tools, and phishing pages impersonating popular download sites. Installation is voluntary, because victims believe they are downloading something legitimate.
- The malware runs silently after installation, extracting every saved credential, URL, and session cookie from all browsers on the device. The extraction takes seconds and produces no visible signs of activity.
- All extracted data is uploaded to a remote server. Logs from thousands of infections are compiled and labeled with raw line counts like "399100" before being cleaned and deduplicated into final files.
- The completed files are distributed through Xavier_Group's Telegram channels as free samples, attracking followers in underground communities and demonstrating the operation's scale to potential premium customers.
Search Your Email: The Xavier_Group Dump Exposed 191 Thousand Accounts
HEROIC's free breach scanner indexes over 400 billion exposed records from stealer logs, database dumps, combolists, and dark web sources. The Xavier_Group January 20, 2026 upload is included in that database. Searching your email address takes under ten seconds.
Visit heroic.com to run a free search. No account is required. If your email appears in this breach or any other indexed source, the results will tell you exactly what was exposed and when. From there, change the affected passwords, enable two-factor authentication on those accounts, and stop reusing passwords across more than one site.
Breach Breakdown
191,479 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds