Xavier Group Users Caught in 419,783-Record Credential Leak
The people caught up in the Xavier_Ulp dump aren't a random sample, they're 419,783 individuals whose devices were compromised and whose saved logins ended up bundled together after a Telegram user uploaded the file on 26-Dec-2025.
Why This Is Dangerous
Anyone using a device that got infected, whether at home, at work, or on a shared computer, could be in this file. The infection doesn't discriminate between personal and seperate professional accounts, it grabs whatever the browser has saved regardless of who the account belongs to.
What Was Exposed
- 419,783 total records
- Email addresses
- Plaintext passwords
- URLs tied to each login
Why This Matters
Because the theft occured directly on the victim's device, there is no telling how many accounts belonging to each person are represented in this file. One infected laptop can produce dozens of stolen logins spanning email, banking, shopping, and social media all at once.
How Stealer Logs Work
Stealer malware infiltrates a device through cracked software, fake updates, or malicious downloads, then scans the browser for saved passwords and autofill data. That stolen information gets packaged into files like Xavier_Ulp and distributed to whoever wants a copy, often for free to build a reputation on Telegram.
Check If You Are Affected
If you think you might be one of the 419,783 people affected, there is a quick way to find out. HEROIC's free breach scanner checks your email against more than 400 billion leaked records so you can confirm your exposure and secure your accounts right away.
Breach Breakdown
419,783 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds