27k Mix UHQ Combo: Emails & Passwords Leaked From US Users
A Stealer Log Dump Surfaces on Telegram
HEROIC analysts identified a credential dump known as "27k Mix UHQ Combo" circulating through a Telegram channel on January 8, 2023. The file contains 25,714 individual records, each pairing an email address with a plaintext password and the web address (URL) where that login was captured. Unlike a breach of a single company, this dataset is a "combo list": credentials pulled from many different websites and services, bundled together by whoever compiled the stealer log.
Why This Is Dangerous
Because the passwords in this dump are stored in plaintext, not hashed or encrypted, anyone who downloads the file can use them immediately with no cracking required. Combined with the URL for each entry, an attacker can go straight to the matching login page and attempt to sign in. If any of these 25,714 people reused the same email and password combination on other sites, banking, shopping, or social media accounts tied to that same email become vulnerable too.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the websites or services each login belongs to
Why This Matters
Combo lists like this one are a favorite tool for credential stuffing attacks, where automated software tries thousands of stolen email and password pairs against other websites in seconds. Anyone whose details appear in this specific mix is at heightened risk of account takeover, particularly on services where they never changed a password that was already exposed elsewhere.
How Stealer Logs Work
Stealer logs come from information-stealing malware that infects a victim's computer, often through pirated software, fake downloads, or phishing links. Once installed, the malware quietly copies saved usernames, passwords, and browser autofill data, then sends everything back to whoever controls the malware. Because the malware pulls data straight from the browser, it captures whatever the victim had saved, across many unrelated sites, which is why a single stealer log often looks like an unrelated "mix" of accounts rather than one company's breach.
Check If You Are Affected
You do not need to know whether your details ended up in this specific combo list to take action. HEROIC's free breach scanner checks your email address against a database of more than 400 billion breached records, including stealer logs like this one, so you can find out quickly whether your information has been exposed and start securing your accounts.
Breach Breakdown
25,714 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds