27.9 Million Logins Leaked in AMRTECH-TXTLOG-ULP-FREE-62 Part 3
HEROIC analysts found a new combolist, AMRTECH-TXTLOG-ULP-FREE-62 Part 3, circulating on Telegram on 17 Jan 2026 with 27,942,731 plaintext email and password pairs attached to the sites they unlock. That is more than twice the population of Australia reduced to one downloadable file, with every password already readable the moment someone opens it. Scanning your email is the only way to know if you're in it.
Why 27.9 Million Plaintext Passwords Is a Worst Case Scenario
There is no cracking, guessing, or waiting involved here. Plaintext means the password sits in the file exactly as it was typed, so a login works the instant someone copies it out. With close to 28 million pairs in one place, automated tools can run through the entire list in minutes, trying each email and password against banking, shopping, and email providers.
The file also tags each pair with the web address it was captured on, so an attacker does not even need to guess where to try first.
Everything Sitting Inside Part 3 of the File
- Email Addresses: identifies exactly who each login belongs to, letting an attacker aim follow up phishing or impersonation at that one address.
- Plaintext Password: readable the moment the file is opened, so it can be used to log in immediately wherever it has been reused.
- URLs: tells an attacker which site each password was captured against, letting them skip straight to the login most likely to work.
What a Leak Like This Actually Costs Someone
Most people reuse the same password across several logins, so one plaintext entry rarely stays contained to a single site. A password lifted from a low value login often unlocks email, shopping, or financial services that share it, which opens the door to fraud, identity theft, and the quiet takeover of logins the victim does not notice until money or data is already gone.
Because the email address is attached directly to the password, recovery options tied to that address can also be targeted, making it easier to lock the real owner out entirely.
Inside the Business of Selling Combolists
A combolist like this one is assembled rather than stolen from a single company in one event. Pairs of emails and passwords pulled from older leaks and infected devices are sorted, cleaned of duplicates, and tagged with the site each one worked on, then packaged into a file like Part 3 and shared on channels like Telegram for others to test against fresh targets. That testing process, often called credential stuffing, is what turns a static list into active break ins.
Is Your Email Among the 27.9 Million in Part 3?
Start by taking a moment to scan your email and see whether it shows up in this file or others like it. If it does, change the password everywhere you have ever reused it, starting with email and anything tied to payment. This matters whether the address you check is personal or one you use for work, since either one being in this file hands an attacker a working door in.
Breach Breakdown
27,942,731 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds