Breach Intelligence Report 12 Jun 2026

Search Your Email: The Xavier_Group Dump Exposed 191K Accounts

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Xavier_Ulp - 399100 Xavier_Group uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 191,479
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts identified this stealer log upload in January 2026, tracking Telegram channels operated by Xavier_Group, an ongoing credential distribution network active in the infostealer underground. The file, labeled "Xavier_Ulp - 399100," contained 191,479 records after deduplication. Each record pairs an email address with a plaintext password and the URL of the website where those credentials were harvested from an infected device. The upload represents the latest in a series of ULP-format batches distributed by Xavier_Group over several months, with this particular file dated January 20, 2026.


Why the Xavier_Group January 20 Upload Is Worth Checking Against Your Email

Stealer log uploads are different from most data breaches because they do not come from one hacked company. They come from thousands of individual infected devices, meaning the email addresses in this file span every kind of website and service imaginable: banking apps, email providers, streaming platforms, government portals, health insurance sites, and everything in between. With 191,479 records spread across that many different URLs, the chances that a specific email address appears in this file, or in one of the many combolists this file will eventually be absorbed into, are significant. A free search takes ten seconds and tells you exactly whether your credentials are in the database.


What the Xavier_Ulp 399100 Upload Exposed

Each of the 191,479 records in this stealer log contains three fields extracted from compromised devices:

  • Email addresses used as login identifiers across web accounts
  • Plaintext passwords captured by infostealer malware before any browser-side encryption could protect them
  • URLs identifying the exact website where each credential pair was active and stolen

The "399100" in the filename reflects the raw line count of the original file before deduplication reduced it to 191,479 unique records. The gap between those two numbers represents duplicate entries, a common feature in stealer logs compiled from multiple infection campaigns targeting the same users across different time periods.


Why This Matters for Account Takeover and Financial Fraud

The Xavier_Group January 20 upload creates immediate and long-term risk for the people in it. Here is how the risk unfolds:

  • Automated credential stuffing tools begin testing the email and password pairs against their target URLs within hours of the file being acquired by a threat actor.
  • Successful logins are used directly for account takeover: draining stored payment methods, initiating password resets on linked services, or selling account access on dark web markets.
  • Even if a specific URL in the log is low-value, the attacker will test the same email and password against high-value targets like Gmail, Outlook, PayPal, and major banks, betting on password reuse.
  • Longer term, the data feeds identity theft operations where stolen credentails are combined with information from other breaches to build complete profiles for fraudulent loan applications and new account fraud.

How Xavier_Group ULP Stealer Logs Are Produced

The ULP format used by Xavier_Group is an industry-standard output from infostealer malware campaigns. ULP stands for URL, Login, and Password, and describes the three-field structure of each record. The production pipeline for these files is consistent:

  1. Infostealer malware reaches victims through pirated software, cracked games, fake productivity tools, and phishing pages impersonating popular download sites. Installation is voluntary, because victims believe they are downloading something legitimate.
  2. The malware runs silently after installation, extracting every saved credential, URL, and session cookie from all browsers on the device. The extraction takes seconds and produces no visible signs of activity.
  3. All extracted data is uploaded to a remote server. Logs from thousands of infections are compiled and labeled with raw line counts like "399100" before being cleaned and deduplicated into final files.
  4. The completed files are distributed through Xavier_Group's Telegram channels as free samples, attracking followers in underground communities and demonstrating the operation's scale to potential premium customers.

Search Your Email: The Xavier_Group Dump Exposed 191 Thousand Accounts

HEROIC's free breach scanner indexes over 400 billion exposed records from stealer logs, database dumps, combolists, and dark web sources. The Xavier_Group January 20, 2026 upload is included in that database. Searching your email address takes under ten seconds.

Visit heroic.com to run a free search. No account is required. If your email appears in this breach or any other indexed source, the results will tell you exactly what was exposed and when. From there, change the affected passwords, enable two-factor authentication on those accounts, and stop reusing passwords across more than one site.

Breach Breakdown

Domain Xavier_Ulp - 399100 Xavier_Group uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 12 Jun 2026
Check in 5 seconds

191,479 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,282 scanned today
Breach Rank #N/A by affected users
Impact Score
8
sensitivity + scale + recency
Est. Financial Impact $1.4M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance