Breach Intelligence Report 13 Jun 2026

Our Analysts Found the Xavier_Ulp 428000 Dump Circulating in Private Telegram Channels

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs Xavier_Ulp - 428000 Xavier_Group uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 268,022
Source Type Stealer log
Origin United States
Password Type plaintext

In May 2026, HEROIC's dark web monitoring analysts found a stealer log file circulating in private Telegram channels under the name Xavier_Ulp - 428000 Xavier_Group. The file contained 268,022 records, each with an email address, a plaintext password, and the URL of the account those credentials belong to. The upload was verified on May 6, 2026, and added to HEROIC's breach database of over 400 billion compromised records.

This batch represents another release from the Xavier_Group campaign, which has now been active and producing uploads for at least five months. The May 2026 release shows the campaign remains operational well into 2026 with no signs of slowing down.


Why the Xavier_Ulp 428000 Credentials Present an Immediate Risk

268,022 plaintext passwords posted to Telegram in May 2026 means those credentials have been in criminal hands for weeks by the time most victims find out. Stealer log files like this one are typically downloaded dozens or hundreds of times in the first 48 hours after posting. Each download represents another potential attacker running credential stuffing tools against the accounts listed in the file.

The URL field in each record is what makes this especially dangerous. Attackers do not spray these credentials randomly across the internet. They go directly to the sites listed for each email and password pair. Your bank's login page, your email provider, your company's HR portal -- if any of those are listed in the file alongside your credentials, that is exactly where the attack will go.


What the Xavier_Ulp 428000 File Exposed

  • Email addresses
  • Plaintext passwords (no hashing, no obfuscation, directly usable)
  • Account URLs identifying the exact services attacked on each infected device

268,022 complete credential records stolen from infected devices. Every password in this file was accurate at the time the malware collected it, representing live, working credentials at the moment of theft.


Why a Xavier_Group File Found in May 2026 Matters

Most stealer log campaigns burn out quickly. Xavier_Group is different. Files uploaded in January, February, March, and now May 2026 demonstrate an operation with lasting infrastructure and ongoing access to a botnet of infected devices. This is not a one-time leak. It is a continuous pipeline.

For people whose credentials appear in the May 2026 batch, the exposure is fresh. Account takeover, identity theft, and unauthorised access to financial accounts are all immediate concerns for anyone whose email appears in this file.

The scale and consistancy of Xavier_Group uploads also suggests the malware is still spreading, meaning new infections are likely still occurring alongside the ongoing releases.


How Our Analysts Found the Xavier_Ulp 428000 Dump Circulating in Private Telegram Channels

HEROIC's dark web monitoring team tracks private Telegram channels, underground forums, and dark web marketplaces for credential leaks on a continuous basis. When a new stealer log file appears, analysts verify its contents, deduplicate records where possible, and index the data into our breach database.

The Xavier_Ulp 428000 file was identified through this monitoring process. It appeared in a private channel that distributes Xavier_Group releases, consistent with the naming and format of previous batches. The file was downloaded, verified, and ingested within hours of its first apearance on that channel.

This kind of monitoring is the only reliable way to detect stealer log releases early, since the victims themselves have no way of knowing their credentials were stolen until they check a breach database or suffer an account compromise directly.


Check If Your Email Is in the Xavier_Ulp 428000 Leak

HEROIC's free breach scanner checks your email address against more than 400 billion compromised records, including the Xavier_Ulp 428000 file and every other Xavier_Group release we have indexed. If your credentials appear in this May 2026 batch, the time to act is now.

Enter your email at HEROIC. If you get a match, change the affected password immediately, ensure you are not reusing that password anywhere else, and enable two-factor authentication on all important accounts. Even if an attacker already has your password, two-factor authentication can prevent them from completing a login.

Breach Breakdown

Domain Xavier_Ulp - 428000 Xavier_Group uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 13 Jun 2026
Check in 5 seconds

268,022 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,045 scanned today
Breach Rank #2,701 by affected users
Impact Score
11
sensitivity + scale + recency
Est. Financial Impact $1.9M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance