The 64K UHQ Combolist: 63,158 Plaintext Passwords, Mixed Domains
HEROIC analysts identified a large combolist known as "64K UHQ Combolist Mixed Domains", uploaded by a Telegram user on February 28, 2023. The file contains 63,158 records pairing email addresses with plaintext passwords, along with URLs identifying the accounts they unlock, spanning multiple different domains rather than a single breached service.
Why the 64K UHQ Combolist Is Dangerous
Attackers label lists like this "UHQ," short for ultra high quality, when they believe the credentials inside are likely to still work. Whether or not every entry remains active, the file gives anyone who downloads it 63,158 ready-to-use email and password combinations, each paired with the URL of the account it unlocks. Because the passwords are stored in plaintext, there is no cracking step standing between an attacker and a working login.
What Was Exposed in the Mixed Domains List
- Email addresses
- Plaintext passwords
- URLs spanning multiple domains
Why This Matters Beyond a Single Site
Because this combolist blends credentials from mixed domains rather than one breached company, its reach is broader than a typical single-site leak. Attackers use combolists like this to run credential stuffing attacks, testing each email and password pair against banking portals, email accounts, and social media platforms. If you have reused a password across services, one leaked entry from this list could open the door to account takeover, identity theft, or financial fraud on accounts far removed from where the credential was first exposed.
How a Combolist Like This Gets Built
A combolist is compiled by combining login pairs pulled from many smaller sources, older breaches, phishing pages, and malware-infected devices, then filtered and merged into one file. The "mixed domains" label on this one signals that its 63,158 records were sourced from a variety of unrelated sites rather than a single breached organization. Once assembled, files like this circulate through Telegram channels and dark web marketplaces, where multiple threat actors download and reuse them for their own credential stuffing campaigns.
Check If You Are Affected
With 63,158 credential pairs in circulation from mixed sources, there is a good chance your email address is included even if you do not recognize any single breached site. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including combolists like this one, so you can find out fast and update any passwords still at risk.
Breach Breakdown
63,158 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds