The ARCEUSULP 120 Data Quietly Appeared on the Dark Web This Month
HEROIC analysts noticed a combolist called ARCEUSULP 120 that quietly appeared on Telegram after a user uploaded it on July 14, 2026. Unlike a major corporate breach announcement, this kind of dump tends to circulate without fanfare, yet the scale is significant: the file contains 4,645,344 records of email addresses, plaintext passwords, and the URLs those credentials were used on.
Why This Is Dangerous
With more than 4.6 million plaintext email and password pairs in one file, an attacker has an enormous ready-made list to work through without any need to crack or decrypt anything. Automated tools can run through combinations like these at high speed, quietly testing each one against the listed URL and against other common services in the hope of finding a reused password. The sheer size of ARCEUSULP 120 means even a small success rate could still translate into thousands of compromised accounts.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs
Why This Matters
A combolist of this size is exactly the kind of raw material that fuels large-scale credential stuffing operations, where criminals batch-test stolen logins across many websites at once. For the millions of people whose information sits inside ARCEUSULP 120, the practical risk depends entirely on whether they reused their password elsewhere. Because the file circulated quietly rather than through a public breach notification, many of those affected likely have no idea their credentials are exposed.
How Combolists Work
A combolist is a plain text file of login pairs, typically formatted as email:password, built from sources such as phishing pages, malware infections, and older data breaches, then merged together into one large file. Combolists of this scale are usually assembled over time from many smaller sources rather than a single event, which is part of why they can appear suddenly on Telegram or dark web forums without any prior public warning. Buyers use them for credential stuffing, account takeover attempts, and reselling smaller curated slices to other criminals.
Check If You Are Affected
With millions of records involved, it is worth checking your own exposure directly rather than waiting for a headline. Run a free scan with HEROIC's breach checker to see if your email address appears in ARCEUSULP 120 or any other leak among more than 400 billion compromised records, and update any password you may have reused.
Breach Breakdown
4,645,344 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds