If You Reuse Passwords, the acenet.com.au Leak Should Worry You
On 10 June 2026, HEROIC analysts identified a combolist tied to the acenet.com.au domain circulating on Telegram, containing 6,959 records that pair an email address with a plaintext password and the URL of the account it opens.
Why This Is Dangerous
Every password in this file is stored in plain, readable text, meaning anyone who downloads it can use the credentials immediately. If you reuse passwords across different sites, a file like this is exactly what lets attackers walk into your other accounts without any hacking skill at all.
What Was Exposed
- Email addresses (tied to the acenet.com.au domain)
- Plaintext passwords
- URLs identifying the account each credential pair belongs to
Why This Matters
With 6,959 credential pairs in this file, attackers have enough volume to run large-scale automated login attempts across banking, email, and shopping sites. Anyone in this list who reused their acenet.com.au password elsewhere is at direct risk of account takeover.
How Combolists Work
Combolists are compiled files of email-and-password pairs, typically assembled from earlier breaches, phishing campaigns, or stealer malware, then shared or sold on Telegram. Attackers load them into credential stuffing software that automatically tests each pair against hundreds of other websites, looking for accounts where the same password still works.
Check If You Are Affected
Search your email address against HEROIC's database of more than 400 billion leaked records, including this acenet.com.au combolist, with a free scan, and update any password you have reused elsewhere.
Breach Breakdown
6,959 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds