The Xavier_Ulp 402800 Leak Has More Records Than Most Cities Have People
In February 2026, HEROIC analysts confirmed the appearance of another Xavier_Ulp stealer log file on a private Telegram channel. This upload, identified as Xavier_Ulp - 402800 Xavier_Group, contained 232,659 records stolen from compromised devices. Every record in the file includes an email address, a plaintext password, and the URL of the account the password belongs to. The data was verified by HEROIC's dark web monitoring team on February 2, 2026, and indexed into our breach database.
This is the second major Xavier_Ulp upload identified by HEROIC, confirming that the Xavier_Group campaign represents an ongoing, organized effort to harvest and distribute stolen credentials at scale.
Why the Xavier_Ulp 402800 Leak Is an Immediate Threat
232,659 plaintext credentials sitting on Telegram is not an abstraction. Each one is a real person's login details for a real account, exposed without any encryption or protection. Because the file pairs email addresses with exact account URLs, attackers don't need to do any extra work. They know which site to hit, which email to use, and which password to try.
This type of packaged stealer log is highly valued by cybercriminals because it removes every guessing step from account takeover. The attacker simply runs an automated tool against the listed URLs, and within hours, they know which accounts are still active and accessible.
What the Xavier_Ulp 402800 Upload Exposed
- Email addresses
- Plaintext passwords (no hashing, no encryption)
- URLs of the targeted accounts and services
With 232,659 records exposed in this format, the potential for immediate account compromise is significant. Plaintext passwords paired with destination URLs represent the most actionable form of stolen credential data.
Why the Xavier_Group Campaign Matters Beyond This Single File
The Xavier_Ulp uploads are not isolated incidents. The naming convention -- Xavier_Ulp with incrementing batch numbers -- suggests a coordinated malware campaign where infected devices feed credentials into a central collection point. Each batch represents a new round of harvesting from a network of compromised machines.
Victims of credential stuffing from stealer logs rarely know their passwords were stolen until an account is compromised. By that point, the attacker may have already changed the password, locked the original owner out, and used the account to commit fraud, send phishing messages, or drain linked payment methods.
The Xavier_Group uploads represent a persistent threat that will continue producing new files. HEROIC monitors for each new release as it appears.
How Stealer Log Campaigns Harvest Credentials at Scale
Stealer log campaigns work by distributing infostealer malware to as many devices as posible. The malware, once installed, silently scans for saved browser passwords, autofill data, and active session cookies. It then packages everything it finds and transmits the bundle to a command-and-control server.
Operators of these campaigns collect thousands of individual device logs and consolidate them into large files, often organized by malware version or campaign batch. These bundles are then sold or freely shared on platforms like Telegram, where they reach a wide audience of cybercriminals who use them for downstream attacks.
The ease of accessing this data is what makes it so dangrous. A buyer doesn't need technical skills. They just need the file and a credential stuffing tool, both of which are freely available.
Check If Your Email Appeared in the Xavier_Ulp 402800 Leak
If your credentials are in this file, they are already in circulation. HEROIC's free breach scanner checks your email address against more than 400 billion compromised records, including this Xavier_Ulp upload and thousands of other breaches.
Search your email now at HEROIC. If you get a match, change the affected password immediately, do not reuse it on any other site, and enable two-factor authentication wherever possible. The sooner you act, the smaller the window attackers have to use your credentials.
Breach Breakdown
232,659 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds