175,196 Plaintext Passwords Dumped in UHQ Private Combolist
HEROIC's dark web monitoring detected a private, high-quality combolist labeled 175k UHQ Private combolist for Mixed sites being circulated on Telegram. Originally surfacing in February 2023, this curated dataset contains 175,196 records of email addresses, plaintext passwords, and associated URLs spanning a wide range of online platforms and services.
Plaintext Credentials at Massive Scale
All 175,196 passwords in this collection are stored in plaintext—completely unencrypted and immediately usable. At this scale, the statistical likelihood that your credentials appear somewhere in this dump increases substantially. Combined with the "UHQ" (Ultra High Quality) classification, which indicates the credentials have been validated for accuracy, this represents one of the more dangerous types of credential dumps: large, verified, and instantly exploitable.
What Was Exposed
- Email Addresses — login identifiers from diverse online services and platforms worldwide
- Plaintext Passwords — validated, unencrypted credentials curated for high success rates
- URLs — login pages across banking, email, social media, shopping, and enterprise applications
Mixed-Site Combos Enable Cross-Platform Attacks
The "Mixed sites" designation means this dump spans credentials from multiple types of online services rather than targeting a single platform. For credential stuffing operations, this diversity is an advantage. Attackers feed the 175,196 pairs into automated tools that test them across every major service—from Gmail and Outlook to Amazon, Netflix, and corporate VPN portals. Password reuse transforms each entry into a potential skeleton key for multiple accounts belonging to the same person.
The Journey from Malware Infection to Private Combolist
Private combolists like this one represent the curated end product of a long infostealer pipeline. The process begins with malware infections—programs like Stealc, RedLine, or Vidar that silently capture saved passwords and session data from browsers. Raw logs from thousands of infected machines are then aggregated, deduplicated, and tested against live login endpoints. Only credentials confirmed to be valid are retained, creating a premium dataset that was originally reserved for private buyer circles before eventually leaking to wider distribution.
Check If Your Credentials Were Exposed
With over 400 billion records in its breach intelligence database, HEROIC offers thorough coverage of stealer log leaks and data breaches worldwide. Use HEROIC's free breach scanner to check if your email address or credentials appear in the 175k UHQ Private combolist or any other known compromise. If a match is found, change the affected password on every service where you used it, switch to unique passwords for each account, and enable two-factor authentication wherever available.
Breach Breakdown
175,196 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds