63 Plaintext Passwords From the MX 3 Combolist Surfaced on Telegram
63 Records Exposed in a Small Telegram Combolist Labeled "MX 3"
HEROIC analysts identified a combolist file named "MX 3" uploaded to Telegram on December 5, 2025. The file is small, containing 63 records of email addresses paired with plaintext passwords along with the URLs where those credentials were used.
Why This Is Dangerous
Small file size does not mean small risk. Every password in this list is stored in plaintext, so anyone who downloads the file can log in to the affected accounts immediately. If any of the 63 people in this file reused their password elsewhere, an attacker can try the same combination on banking, email, or shopping accounts right away.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each set of credentials
Why This Matters
Small combolists like this one are often combined with other lists to build larger collections used for credential stuffing, where automated tools test stolen logins against dozens of websites at once. Because these passwords were never hashed, there is nothing standing between exposure and account takeover for anyone who reused this password.
How a Combolist Like This Is Assembled
A combolist is a plain text file listing email or username and password pairs, typically gathered from smaller breaches, phishing pages, or stealer malware and then shared on Telegram or sold in bulk. Small files like this one are often test batches or fragments that get merged into bigger compilations over time.
Check If You Are Affected
If you want to know whether your email address and password show up in this leak or any other, HEROIC's free breach scanner checks your information against more than 400 billion leaked records so you can find out and secure your accounts.
Breach Breakdown
63 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds