Adult Site Users Targeted: 800K Porn Combo Exposes Passwords
HEROIC's threat intelligence systems flagged a stealer log file titled "800K Porn Combo" that was uploaded to Telegram in January 2023. The file contains 799,626 stolen credential records harvested from adult websites, each entry pairing an email address with a plaintext password and the specific URL where it was used. The sensitive nature of this data amplifies the potential damage far beyond typical account compromise.
Plaintext Passwords Mean Instant Exploitation
Every password in this collection is stored without encryption or hashing. Anyone who downloads the 800K Porn Combo file can read the credentials directly and attempt logins immediately. For adult site credentials, the stakes are even higher — beyond account access, the mere association of an email address with these sites can be used for blackmail, extortion, or social engineering against the affected individuals.
What Was Exposed
- Email Addresses — personal identifiers that link individuals to adult content platforms
- Plaintext Passwords — fully readable credentials requiring no decryption to exploit
- URLs — the specific adult websites where each credential was captured, revealing browsing activity
Password Reuse Multiplies the Damage
Many people use the same password for adult sites that they use for email, banking, and social media. Attackers know this and run credential-stuffing attacks that test each stolen pair across hundreds of mainstream services. A password originally saved for an adult site can give criminals access to your primary email, financial accounts, and cloud storage. The 799,626 credentials in this dump represent nearly 800,000 starting points for these automated attacks.
How Infostealer Malware Harvested This Data
The credentials in this file were extracted by infostealer malware running on victims' devices. Programs like RedLine, Raccoon, and Lumma Stealer capture every saved password from web browsers, along with cookies, autofill data, and browsing history. The malware transmits everything to remote servers, where operators compile the data into themed collections. The "Porn Combo" label indicates this set was filtered specifically for adult site credentials before being distributed on Telegram.
Check If Your Credentials Were Exposed
With nearly 800,000 records in this single file, the risk of your credentials being included is significant. HEROIC's data breach scanner lets you search through more than 400 billion compromised records to determine whether your email or password has been exposed in this or any other leak. Taking a few seconds to check can prevent account takeover, identity theft, and extortion attempts.
Breach Breakdown
799,626 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds