The Alice.de Combolist Put 229 Login Pairs Online This Week
What HEROIC Analysts Found in the Alice.de Combolist Leak
In July 2026, HEROIC analysts identified a small combolist tied to the domain alice.de, uploaded to a Telegram channel by an anonymous user. The file contained 229 records of email addresses paired with plaintext passwords and the URLs those credentials were used on.
Why This Is Dangerous
Even a small file like this one carries real risk for the people in it. The plaintext passwords and matching website URLs mean an attacker does not need to do any extra work: the credentials are ready to test the moment the file is downloaded.
What Was Exposed in the Alice.de Combolist
- Email addresses
- Plaintext passwords
- URLs of the associated websites
Why This Matters for the 229 Affected Accounts
Small combolists like this one are still routinely used for credential stuffing, and a low record count does not mean low risk for the individuals involved. Anyone among the 229 affected accounts who reused a password on another site faces a real chance of account takeover, identity theft, or financial fraud.
How a Domain-Specific Combolist Like This Gets Built
Some combolists are built around a single domain or provider, gathering credentials specifically tied to that service from older breaches or stealer logs, then packaging them for sale or free distribution through channels like Telegram, as happened here.
Check If You Are Affected
If you want to know whether your email address is part of this leak or any other breach, HEROIC's free breach scanner checks your information against more than 400 billion leaked records. Run a scan today to see your exposure and secure your accounts.
Breach Breakdown
229 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds