Our Analysts Found the Xavier_Ulp 428000 Dump Circulating in Private Telegram Channels
In May 2026, HEROIC's dark web monitoring analysts found a stealer log file circulating in private Telegram channels under the name Xavier_Ulp - 428000 Xavier_Group. The file contained 268,022 records, each with an email address, a plaintext password, and the URL of the account those credentials belong to. The upload was verified on May 6, 2026, and added to HEROIC's breach database of over 400 billion compromised records.
This batch represents another release from the Xavier_Group campaign, which has now been active and producing uploads for at least five months. The May 2026 release shows the campaign remains operational well into 2026 with no signs of slowing down.
Why the Xavier_Ulp 428000 Credentials Present an Immediate Risk
268,022 plaintext passwords posted to Telegram in May 2026 means those credentials have been in criminal hands for weeks by the time most victims find out. Stealer log files like this one are typically downloaded dozens or hundreds of times in the first 48 hours after posting. Each download represents another potential attacker running credential stuffing tools against the accounts listed in the file.
The URL field in each record is what makes this especially dangerous. Attackers do not spray these credentials randomly across the internet. They go directly to the sites listed for each email and password pair. Your bank's login page, your email provider, your company's HR portal -- if any of those are listed in the file alongside your credentials, that is exactly where the attack will go.
What the Xavier_Ulp 428000 File Exposed
- Email addresses
- Plaintext passwords (no hashing, no obfuscation, directly usable)
- Account URLs identifying the exact services attacked on each infected device
268,022 complete credential records stolen from infected devices. Every password in this file was accurate at the time the malware collected it, representing live, working credentials at the moment of theft.
Why a Xavier_Group File Found in May 2026 Matters
Most stealer log campaigns burn out quickly. Xavier_Group is different. Files uploaded in January, February, March, and now May 2026 demonstrate an operation with lasting infrastructure and ongoing access to a botnet of infected devices. This is not a one-time leak. It is a continuous pipeline.
For people whose credentials appear in the May 2026 batch, the exposure is fresh. Account takeover, identity theft, and unauthorised access to financial accounts are all immediate concerns for anyone whose email appears in this file.
The scale and consistancy of Xavier_Group uploads also suggests the malware is still spreading, meaning new infections are likely still occurring alongside the ongoing releases.
How Our Analysts Found the Xavier_Ulp 428000 Dump Circulating in Private Telegram Channels
HEROIC's dark web monitoring team tracks private Telegram channels, underground forums, and dark web marketplaces for credential leaks on a continuous basis. When a new stealer log file appears, analysts verify its contents, deduplicate records where possible, and index the data into our breach database.
The Xavier_Ulp 428000 file was identified through this monitoring process. It appeared in a private channel that distributes Xavier_Group releases, consistent with the naming and format of previous batches. The file was downloaded, verified, and ingested within hours of its first apearance on that channel.
This kind of monitoring is the only reliable way to detect stealer log releases early, since the victims themselves have no way of knowing their credentials were stolen until they check a breach database or suffer an account compromise directly.
Check If Your Email Is in the Xavier_Ulp 428000 Leak
HEROIC's free breach scanner checks your email address against more than 400 billion compromised records, including the Xavier_Ulp 428000 file and every other Xavier_Group release we have indexed. If your credentials appear in this May 2026 batch, the time to act is now.
Enter your email at HEROIC. If you get a match, change the affected password immediately, ensure you are not reusing that password anywhere else, and enable two-factor authentication on all important accounts. Even if an attacker already has your password, two-factor authentication can prevent them from completing a login.
Breach Breakdown
268,022 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds