1,852 Emails From acsu.buffalo.edu Just Surfaced on the Dark Web
On 10 June 2026, HEROIC analysts found a combolist tied to acsu.buffalo.edu circulating on Telegram, containing 1,852 records that pair an email address with a plaintext password and the URL of the account it unlocks.
Why This Is Dangerous
Because the passwords in this file are stored as plain, readable text, anyone who downloads it can use the credentials immediately. Attackers typically load lists like this into automated tools that try each email and password pair against email providers, banking sites, and other services the same person might use.
What Was Exposed
- Email addresses (tied to the acsu.buffalo.edu domain)
- Plaintext passwords
- URLs identifying the account each credential pair belongs to
Why This Matters
Accounts linked to a university email address are often reused to sign into personal email, banking apps, and shopping sites. If anyone among the 1,852 exposed accounts reused their password elsewhere, an attacker already has what they need to try breaking into those other accounts too.
How Combolists Work
A combolist is a plain text file of "email:password" pairs, usually gathered from earlier breaches, phishing pages, or malware-infected devices, then bundled together and shared on Telegram. Criminals feed these files into credential stuffing tools that automatically test each pair across hundreds of websites, looking for accounts where the password still works.
Check If You Are Affected
Search your email address in HEROIC's database of more than 400 billion leaked records, including this acsu.buffalo.edu combolist, with a free scan. If you find a match, change that password everywhere you have reused it.
Breach Breakdown
1,852 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds