Search Your Email: The Xavier_Ulp 410100 Dump Exposed 280,344 Accounts
In March 2026, HEROIC analysts identified another release in the Xavier_Group stealer log campaign. The file, uploaded to a private Telegram channel under the name Xavier_Ulp - 410100 Xavier_Group, contained 280,344 records. Each record includes an email address, a plaintext password, and the URL of the account those credentials belong to. HEROIC's dark web monitoring team verified the data on March 9, 2026, and indexed it into our breach database of over 400 billion compromised records.
The 410100 batch marks at least the fourth identifiable Xavier_Group upload, confirming the campaign continues to produce new credential dumps months after its initial appearance in January 2026.
Why the Xavier_Ulp 410100 Credentials Are a Direct Threat to Your Accounts
When a stealer log includes plaintext passwords and account URLs together, the threat to victims is immediate and specific. An attacker doesn't need to invest time cracking hashed passwords or guessing which websites a person uses. The file does both of those jobs automatically.
280,344 people in this file had their login details extracted from their own devices by malware and handed to criminals. For anyone in this file who still uses the same password on other accounts, that credential is a key that can open multiple doors at once. Email, banking, social media, and workplace accounts are all common targets once a single working credential is confirmed.
What the Xavier_Ulp 410100 Upload Exposed
- Email addresses
- Plaintext passwords (no encryption or obfuscation of any kind)
- Account URLs pinpointing exactly which services were accessed
Every one of the 280,344 records in this file was stolen from an infected device. The passwords were accurate and active at the time of collection, making them high-value for immediate use in credential stuffing attacks.
Why the Xavier_Group Campaign Keeps Producing New Files
Stealer log campaigns like Xavier_Group are designed for longevity. The infrastructure runs continuously, infecting new devices and collecting new credentials without requiring ongoing manual effort from the operators. Each batch upload represents another harvest cycle from a botnet of compromised machines.
For victims, the ongoing nature of the campaign means the risk doesn't end with a single leak. New files may include updated credentials from the same victims whose older passwords were already changed. Attackers who buy into the Xavier_Group feed receive a steady stream of fresh data rather than a single static file.
Account takeover fraud, identity theft, and unauthorised finantial transactions are the typical end results for people whose data appears in these files.
How Xavier_Ulp Stealer Logs Are Built From Infected Devices
The process behind a stealer log like Xavier_Ulp 410100 begins on individual victims' computers. Infostealer malware, delivered through malicious downloads, cracked software, or phishing attacks, installs itself silently and begins extracting saved credentials from browsers and applications.
The malware specifically targets password storage in browsers like Chrome and Firefox, where most people store dozens or hundreds of saved logins. It also captures autofill data, session tokens, and stored form data. All of this is bundled into a log file and transmitted back to the attacker's infrastructure automatically.
Thousands of these individual device logs are then merged and organized by campaign batch, producing files like Xavier_Ulp 410100 that are uploaded to Telegram and sold or freely shared with other criminals. The entire process from infection to Telegram upload can take less than 24 ours in active campaigns.
Search Your Email: Find Out If You Are in the Xavier_Ulp 410100 Leak
If your email address appears in the Xavier_Ulp 410100 file, your credentials have been available to criminals since March 2026. The longer that window stays open, the more likely a successful attack becomes.
HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including all known Xavier_Group uploads. Enter your email at HEROIC now to see if you are affected. If you find a match, change the associated password immediately, use a unique password for every site, and enable two-factor authentication to reduce the risk of account takeover even if your password is already known.
Breach Breakdown
280,344 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds