The ‘2K SAMPLE’ Leak: 2,088 GMX and Onet Passwords Exposed
HEROIC analysts found a combolist titled "2K SAMPLE gmx onet," uploaded to Telegram in August 2026. The file contains 2,088 records pairing email addresses on the GMX and Onet platforms with plaintext passwords and associated login URLs.
Why This Is Dangerous
Be direct about what this means: 2,088 real people had their email address and password exposed together, in plaintext, in a file explicitly targeting two specific webmail providers. If your GMX or Onet password is in this file and you've used it anywhere else, that other account is at risk right now.
What Was Exposed
- GMX and Onet email addresses
- Plaintext passwords
- Associated login URLs
Why This Matters
GMX and Onet are widely used webmail services in Germany and Poland, respectively, which makes a targeted combolist like this one especially efficient for attackers running credential stuffing campaigns against users in those regions. Password reuse is what turns a leaked email login into a compromised bank account or social media profile.
How Combolists Work
The "SAMPLE" label here signals that this 2,088-record file is likely a preview of a larger batch, meant to demonstrate the data's quality before a bigger sale. Combolists like this are compiled from older leaks, phishing pages, and stealer malware output, then filtered by email provider, in this case GMX and Onet, so buyers can target a specific user base.
Check If You Are Affected
Check your email address now with HEROIC's free breach scanner, covering more than 400 billion leaked records, to find out if your GMX or Onet account is in this sample or any related exposure.
Breach Breakdown
2,088 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds