Analysts Flag the Orange.fr Sample Leak: 199 French Accounts Exposed
HEROIC analysts found this file on Telegram on March 17, 2026. The uploader labeled it ORANGE.FR SAMPLE, and it contains 199 records of email addresses and plaintext passwords with login URLs. The name suggests these accounts are tied to Orange, the French telecom provider, and the word sample indicates this is likely a small preview of a larger file being offered elsewhere. Why This Is Dangerous: Telecom and internet provider accounts often control a person's phone number, billing information, and sometimes two-factor authentication settings. A working login here could let an attacker view billing details, change account settings, or intercept messages tied to that account. What Was Exposed: - Email addresses - Plaintext passwords - Login URLs Why This Matters: The sample labeling is worth taking seriously. Sellers commonly release a small sample like this 199-record file to prove a larger stolen data set is real before selling the full version, which means more records tied to this same source may exist beyond what HEROIC has directly reviewed. How a Sample Combolist Like This Works: Sample files are a common sales tactic on Telegram and dark web marketplaces. A seller releases a small, verified slice of a larger stolen data set for free, letting potential buyers confirm the data is genuine before paying for the complete list, which may contain far more records than the sample alone. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion breached and leaked records. Run a free scan to see if your Orange or other telecom account credentials have been exposed.
Breach Breakdown
199 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds