The aexp.com Leak Could Open the Door to Your Email and More
On June 10, 2026, HEROIC's dark web monitoring team found a combolist circulating on Telegram labeled "aexp.com - 580 emails." The file contains 580 records pairing email addresses tied to the aexp.com domain with plaintext passwords and the URLs those logins were used on.
Why the aexp.com Leak Is Dangerous
Because the passwords in this file are stored in plaintext, anyone who downloads it can read every credential instantly. When the exposed accounts are tied to a single domain like this one, attackers can focus their efforts on that one login page, increasing the odds of a successful break-in.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each login
Why This Matters for Your Accounts
If a password from this leak has been reused anywhere else, financial, email, or shopping accounts included, an attacker can use credential stuffing to test that same combination broadly. One reused password can quickly turn into access to several parts of your digital life.
How This Combolist Was Built
A combolist pairs usernames or emails with passwords, one per line, usually assembled from older breaches, phishing pages, and malware-infected devices. Domain-focused files like this one group together every login tied to a specific email domain, making it easier for an attacker to target that group directly.
Check If You Are Affected
HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this leak. Run a scan to see if your information was exposed, and get clear steps to secure your accounts.
Breach Breakdown
580 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds