Xavier_Group Breach Leaks 336,725 Passwords Online
Security researchers at HEROIC monitoring Telegram channels in December 2025 came across a stealer log dataset labeled Xavier_Ulp - 480600 Xavier_Group. The file contained 336,725 records, each one linking a stolen email address to a plaintext password and the exact website URL that password unlocked.
Why This Is Dangerous
At over 300,000 records, this dataset gives an attacker enormous reach. Every credential is stored in readable plaintext next to its matching login page, so there's no code to break, no encryption to bypass. It's simply a matter of copying the data and trying it.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated login URLs
Why This Matters
A leak this large becomes fuel for mass credential stuffing campaigns, where automated bots test stolen logins against hundreds of other services in seconds. For the people caught in it, that often means account takeover on email or banking platforms, followed by identity theft or outright financial fraud.
How Stealer Logs Work
Files like Xavier_Ulp are the output of info-stealing malware that spreads through pirated software, fake installers, or malicious downloads. Once active on a victim's computer, the malware quietly extracts every saved password and cookie from the browser, packaging hundreds of thousands of records into a single log that gets shared or sold in bulk, as seen with this 336,725-record file.
Check If You Are Affected
Given the sheer size of this leak, checking your exposure is worth doing today. HEROIC's free breach scanner searches across more than 400 billion compromised records, this dataset included, and shows you instantly if your information is at risk.
Breach Breakdown
336,725 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds