The Aetna.com Leak: 2,185 Passwords Exposed. Yours Might Be One.
HEROIC analysts found a combolist containing email addresses on the aetna.com domain, uploaded to a Telegram channel on June 10, 2026. The file lists 2,185 records combining email addresses with plaintext passwords and the URLs each credential was used on. This reflects addresses using the aetna.com domain found in a combolist, not a confirmed breach of Aetna's own systems. Why This Is Dangerous: These are real, working email and password combinations, not guesses. Anyone holding this file can attempt to log into the exact accounts listed, whether that's a work account, a personal account, or a third-party service tied to that email address. What Was Exposed: The file lists three data points for each of its 2,185 records. - Email addresses on the aetna.com domain - Plaintext passwords - URLs showing where each login was used Why This Matters: When work email addresses turn up in a combolist, the risk extends past the individual account. Reused passwords can open the door to other personal accounts, and if any of these credentials unlock internal systems, the exposure could lead to broader account takeover or fraud. How a Combolist Like This Works: This file was likely built by pulling entries tied to a specific domain out of larger stealer logs or breach compilations, a common technique for creating targeted lists sold or shared on Telegram. The narrow focus on one domain makes lists like this appealing to attackers running phishing or credential stuffing campaigns against a specific organization's email addresses. Check If You Are Affected: Search your email with HEROIC's free breach scanner, covering more than 400 billion breached records, to see if your aetna.com address or any other account appears in this or another leak.
Breach Breakdown
2,185 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds