Breach Intelligence Report 14 Jul 2026

175,196 Plaintext Passwords Dumped in UHQ Private Combolist

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs 175k UHQ Private combolist for Mixed sites uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 175,196
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC's dark web monitoring detected a private, high-quality combolist labeled 175k UHQ Private combolist for Mixed sites being circulated on Telegram. Originally surfacing in February 2023, this curated dataset contains 175,196 records of email addresses, plaintext passwords, and associated URLs spanning a wide range of online platforms and services.


Plaintext Credentials at Massive Scale

All 175,196 passwords in this collection are stored in plaintext—completely unencrypted and immediately usable. At this scale, the statistical likelihood that your credentials appear somewhere in this dump increases substantially. Combined with the "UHQ" (Ultra High Quality) classification, which indicates the credentials have been validated for accuracy, this represents one of the more dangerous types of credential dumps: large, verified, and instantly exploitable.


What Was Exposed

  • Email Addresses — login identifiers from diverse online services and platforms worldwide
  • Plaintext Passwords — validated, unencrypted credentials curated for high success rates
  • URLs — login pages across banking, email, social media, shopping, and enterprise applications

Mixed-Site Combos Enable Cross-Platform Attacks

The "Mixed sites" designation means this dump spans credentials from multiple types of online services rather than targeting a single platform. For credential stuffing operations, this diversity is an advantage. Attackers feed the 175,196 pairs into automated tools that test them across every major service—from Gmail and Outlook to Amazon, Netflix, and corporate VPN portals. Password reuse transforms each entry into a potential skeleton key for multiple accounts belonging to the same person.


The Journey from Malware Infection to Private Combolist

Private combolists like this one represent the curated end product of a long infostealer pipeline. The process begins with malware infections—programs like Stealc, RedLine, or Vidar that silently capture saved passwords and session data from browsers. Raw logs from thousands of infected machines are then aggregated, deduplicated, and tested against live login endpoints. Only credentials confirmed to be valid are retained, creating a premium dataset that was originally reserved for private buyer circles before eventually leaking to wider distribution.


Check If Your Credentials Were Exposed

With over 400 billion records in its breach intelligence database, HEROIC offers thorough coverage of stealer log leaks and data breaches worldwide. Use HEROIC's free breach scanner to check if your email address or credentials appear in the 175k UHQ Private combolist or any other known compromise. If a match is found, change the affected password on every service where you used it, switch to unique passwords for each account, and enable two-factor authentication wherever available.

Breach Breakdown

Domain 175k UHQ Private combolist for Mixed sites uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 14 Jul 2026
Check in 5 seconds

175,196 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 2,666 scanned today
Breach Rank #N/A by affected users
Impact Score
7
sensitivity + scale + recency
Est. Financial Impact $1.3M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance