Your Data May Be at Risk: the 90K SFR.FR Combo Held 84,444 Logins
In June 2023, a Telegram user uploaded a file labeled 90K SFR.FR Combo. Our analysts verified the actual contents and found 84,444 usable records, somewhat fewer than the name suggests but still a substantial set of email addresses paired with plaintext passwords and the login URLs they were captured from. Why This Is Dangerous: Whether the true count is 90,000 or 84,444, the danger to each person in the file is identical. The passwords are stored in plain, readable text, so anyone who obtains the file can log in immediately without cracking anything. What Was Exposed: - Email addresses - Plaintext passwords - Login URLs for each account Why This Matters: A confirmed 84,444 working credentials is more than enough to fuel an automated credential stuffing campaign. Attackers load lists like this into tools that quietly test each login across dozens of unrelated sites, looking for reused passwords. A single match can lead to a hijacked email account, stolen personal information, or direct financial fraud. How a Combolist Like This Works: Combolists like this one are pulled together from older breaches, phishing kits, or malware-infected devices, then filtered down to a specific provider, in this case SFR.fr addresses, and given an inflated round number to make the listing look more attractive to buyers. The gap between the advertised size and the real count is common in these Telegram marketplaces. Check If You Are Affected: Use HEROIC's free breach scanner to check your email address against more than 400 billion exposed records, including this one. If you get a match, change your password right away and anywhere else you have reused it.
Breach Breakdown
84,444 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds