Our Analysts Found the ‘usa mailaccess’ Dump in a Telegram Channel
HEROIC analysts found a combolist titled "usa mailaccess" circulating in a Telegram channel, dated to December 2022. The file contains 2,378 records pairing email addresses, tied to US webmail accounts, with plaintext passwords and their associated login URLs.
Why This Is Dangerous
Files like this rarely announce themselves loudly. They circulate quietly among smaller Telegram groups and resale channels long before anyone outside that circle notices, which means the accounts inside can be tested and exploited for months before the people affected have any idea their credentials are out there.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated login URLs
Why This Matters
Webmail accounts are a common target precisely because they unlock so much else: password resets, two-factor codes, and account recovery flows all typically run through email. A compromised webmail login from a file like "usa mailaccess" can quickly become a compromised bank account or shopping account too.
How Combolists Work
A combolist is an assembled file of email/username and password pairs, usually pulled together from older leaks and malware logs rather than one single hack. The "usa mailaccess" name suggests this batch was filtered specifically for US-based webmail logins, a common way sellers segment their inventory for buyers with a specific target in mind.
Check If You Are Affected
Check your email address against HEROIC's free breach scanner, which draws on more than 400 billion leaked records, to see if your credentials surfaced in this combolist or elsewhere.
Breach Breakdown
2,378 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds