41,680 Phone-Linked Accounts From the China Phone Valid Leak Surfaced
HEROIC analysts identified a combolist called China Phone Valid, uploaded to a Telegram channel and dated April 5, 2025. The file contains 41,680 records, each combining an email address with a plaintext password and the URL that credential was used on. Why This Is Dangerous: The valid label indicates these credentials were tested and confirmed to work before distribution. With over 41,000 confirmed working logins in one file, attackers have real scale to run automated attacks without wasting time on dead accounts. What Was Exposed: Every one of the 41,680 records in this file contains the same three data points. - Email addresses - Plaintext passwords - URLs showing which site each login belongs to Why This Matters: A verified list this size is built for credential stuffing at scale, testing the same stolen passwords across banking, shopping, and social accounts to catch anyone who reused a login. The confirmed-valid status makes account takeover and downstream fraud more likely, not less. How a Combolist Like This Works: Files labeled phone valid or similar typically combine credentials tied to phone-verified accounts, then run through a checking process to confirm which logins still work before being packaged for Telegram distribution. That verification step is what separates a raw dump from a valid list like this one. Check If You Are Affected: Search your email using HEROIC's free breach scanner, which checks against more than 400 billion leaked records, to see if you're among the 41,680 accounts in the China Phone Valid file.
Breach Breakdown
41,680 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds