Breach Intelligence Report 12 Jun 2026

Search Your Email: The Xavier_Ulp 410100 Dump Exposed 280,344 Accounts

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Xavier_Ulp - 410100 Xavier_Group uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 280,344
Source Type Stealer log
Origin United States
Password Type plaintext

In March 2026, HEROIC analysts identified another release in the Xavier_Group stealer log campaign. The file, uploaded to a private Telegram channel under the name Xavier_Ulp - 410100 Xavier_Group, contained 280,344 records. Each record includes an email address, a plaintext password, and the URL of the account those credentials belong to. HEROIC's dark web monitoring team verified the data on March 9, 2026, and indexed it into our breach database of over 400 billion compromised records.

The 410100 batch marks at least the fourth identifiable Xavier_Group upload, confirming the campaign continues to produce new credential dumps months after its initial appearance in January 2026.


Why the Xavier_Ulp 410100 Credentials Are a Direct Threat to Your Accounts

When a stealer log includes plaintext passwords and account URLs together, the threat to victims is immediate and specific. An attacker doesn't need to invest time cracking hashed passwords or guessing which websites a person uses. The file does both of those jobs automatically.

280,344 people in this file had their login details extracted from their own devices by malware and handed to criminals. For anyone in this file who still uses the same password on other accounts, that credential is a key that can open multiple doors at once. Email, banking, social media, and workplace accounts are all common targets once a single working credential is confirmed.


What the Xavier_Ulp 410100 Upload Exposed

  • Email addresses
  • Plaintext passwords (no encryption or obfuscation of any kind)
  • Account URLs pinpointing exactly which services were accessed

Every one of the 280,344 records in this file was stolen from an infected device. The passwords were accurate and active at the time of collection, making them high-value for immediate use in credential stuffing attacks.


Why the Xavier_Group Campaign Keeps Producing New Files

Stealer log campaigns like Xavier_Group are designed for longevity. The infrastructure runs continuously, infecting new devices and collecting new credentials without requiring ongoing manual effort from the operators. Each batch upload represents another harvest cycle from a botnet of compromised machines.

For victims, the ongoing nature of the campaign means the risk doesn't end with a single leak. New files may include updated credentials from the same victims whose older passwords were already changed. Attackers who buy into the Xavier_Group feed receive a steady stream of fresh data rather than a single static file.

Account takeover fraud, identity theft, and unauthorised finantial transactions are the typical end results for people whose data appears in these files.


How Xavier_Ulp Stealer Logs Are Built From Infected Devices

The process behind a stealer log like Xavier_Ulp 410100 begins on individual victims' computers. Infostealer malware, delivered through malicious downloads, cracked software, or phishing attacks, installs itself silently and begins extracting saved credentials from browsers and applications.

The malware specifically targets password storage in browsers like Chrome and Firefox, where most people store dozens or hundreds of saved logins. It also captures autofill data, session tokens, and stored form data. All of this is bundled into a log file and transmitted back to the attacker's infrastructure automatically.

Thousands of these individual device logs are then merged and organized by campaign batch, producing files like Xavier_Ulp 410100 that are uploaded to Telegram and sold or freely shared with other criminals. The entire process from infection to Telegram upload can take less than 24 ours in active campaigns.


Search Your Email: Find Out If You Are in the Xavier_Ulp 410100 Leak

If your email address appears in the Xavier_Ulp 410100 file, your credentials have been available to criminals since March 2026. The longer that window stays open, the more likely a successful attack becomes.

HEROIC's free breach scanner checks your email against more than 400 billion compromised records, including all known Xavier_Group uploads. Enter your email at HEROIC now to see if you are affected. If you find a match, change the associated password immediately, use a unique password for every site, and enable two-factor authentication to reduce the risk of account takeover even if your password is already known.

Breach Breakdown

Domain Xavier_Ulp - 410100 Xavier_Group uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 12 Jun 2026
Check in 5 seconds

280,344 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,787 scanned today
Breach Rank #N/A by affected users
Impact Score
11
sensitivity + scale + recency
Est. Financial Impact $2.0M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance