5,012 aapanel Admin Panel Logins Just Leaked on Telegram
HEROIC analysts found this file on Telegram on July 28, 2026. A Telegram user uploaded a combolist named aapanel containing 5,012 records of email addresses and plaintext passwords tied to aaPanel server management login URLs. Why This Is Dangerous: aaPanel is a free control panel used to manage web servers, including websites, databases, and files. A working aaPanel login can hand an attacker full administrative control over a server, which is far more damaging than a single stolen account. What Was Exposed: - Email addresses - Plaintext passwords - aaPanel login URLs Why This Matters: Server administrators and small business owners who rely on aaPanel to manage their websites are the most directly affected group here. If your login is in this file, an attacker could take down your website, install malware for your visitors, or access any customer data stored on that server. How a Server Panel Combolist Like This Works: Attackers scan the internet for servers running control panel software like aaPanel, then attempt to steal or guess login credentials through weak passwords, exposed configuration files, or known software vulnerabilities. Once collected, thousands of working logins like these 5,012 records get bundled into a single combolist for sale or trade. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion breached and leaked records. Run a free scan today, and if you manage a server with aaPanel, change your admin password as a precaution.
Breach Breakdown
5,012 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds