9,932 Accounts Exposed in a Telegram ‘Random Test USA Mix’ Leak
HEROIC analysts found a combolist file labeled random test USA and mix 2 uploaded to a Telegram channel on June 14, 2026. Despite the informal, test-like name, the file is real and contains 9,932 records pairing an email address or username with a plaintext password and a URL. Why This Is Dangerous: The name suggests this may have started as a small test batch, but the credentials inside are live data, not a demo. Every password is stored in plaintext, so anyone who gets the file can immediately try each login on other websites without needing to crack or decode anything. What Was Exposed: - Email addresses and usernames - Plaintext passwords - URLs tied to each login Why This Matters: Even a modest-sized file like this one is enough to fuel credential stuffing attacks, where automated tools test each email and password pair against banking sites, email providers, and shopping accounts. If you reused a password that appears in this list anywhere else, that account is at risk of takeover, fraud, or identity theft, regardless of how small the original file looks. How a Combolist Like This Works: A combolist is a plain text file of username or email and password pairs, often assembled by combining smaller batches of stolen data from stealer logs or older breaches. Files like this one get shared and re-uploaded across Telegram channels, sometimes with casual or test-sounding names, but the underlying credentials can still be used against real accounts. Check If You Are Affected: Rather than wonder whether your information ended up in a file like this, run your email through HEROIC's free breach scanner. It checks against a database of more than 400 billion leaked records so you can see instantly if you need to change a password.
Breach Breakdown
9,932 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds