The “6k” Combolist Dump: 4,746 Stolen Logins Hit the Dark Web
What HEROIC Analysts Found in the "6k" Combolist Leak
In October 2025, HEROIC analysts identified a combolist labeled "6k," uploaded to a Telegram channel by an anonymous user. The file contained 4,746 records of email addresses paired with plaintext passwords and the URLs those credentials were originally used on.
Why This Is Dangerous
Because every password in the "6k" file is stored in plaintext and matched to a specific site URL, an attacker can move straight from download to login attempt with no extra effort required to crack or guess anything.
What Was Exposed in the "6k" Combolist
- Email addresses
- Plaintext passwords
- URLs of the associated websites
Why This Matters for the 4,746 Affected Accounts
A file of this size gives attackers enough volume to run an automated credential stuffing campaign across banking, retail, and social media logins. Anyone among the 4,746 affected accounts who reused a password elsewhere is at meaningful risk of account takeover, identity theft, or financial fraud.
How Combolists Like "6k" Get Made
Files like this are assembled from a mix of older breaches and stealer malware logs, then labeled with a shorthand name referencing their approximate size before being shared or sold through Telegram channels, as this one was.
Check If You Are Affected
To find out if your email address appears in the "6k" combolist or any other leak, run a free scan with HEROIC's breach scanner, which checks against more than 400 billion leaked records, and get clear steps to secure your accounts.
Breach Breakdown
4,746 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds