1,422 Passwords From the “Good” Combolist Surface on Dark Web
What HEROIC Analysts Found in the "Good" Combolist Leak
In November 2025, HEROIC analysts identified a combolist labeled "good," uploaded to a Telegram channel by an anonymous user. The file contained 1,422 records of email addresses paired with plaintext passwords and the URLs those credentials were originally used on.
Why This Is Dangerous
The label "good" is a common shorthand compilers use to claim that the credentials in a file are current and working. Whether or not that claim holds up, the plaintext passwords and matching site URLs give an attacker everything needed to attempt a login right away.
What Was Exposed in the "Good" Combolist
- Email addresses
- Plaintext passwords
- URLs of the associated websites
Why This Matters for the 1,422 Affected Accounts
A file of this size is easily large enough to fuel automated credential stuffing attempts against banking, email, and retail logins. Anyone among the 1,422 affected accounts who reused a password on another site faces real risk of account takeover, identity theft, or financial fraud.
How Combolists Like "Good" Get Made
Combolists are pieced together from older breaches and stealer malware logs, then labeled with simple terms like "good" to signal quality to potential buyers before being shared or sold through Telegram, as this file was.
Check If You Are Affected
To find out if your email address is part of this "good" combolist or any other leak, run a free scan with HEROIC's breach scanner, which checks against more than 400 billion leaked records, and learn how to secure any exposed accounts.
Breach Breakdown
1,422 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds