The ARCEUSULP Combolist Quietly Exposed 2.7 Million Records
A Combolist Named ARCEUSULP Surfaces With Millions of Records
In June 2026, HEROIC analysts identified a combolist file known as ARCEUSULP that had been uploaded to Telegram, containing 2,668,775 records of email addresses, plaintext passwords, and the URLs those credentials were tied to. This is one of the larger combolists analysts have tracked recently, combining login data from a wide range of sources into a single file.
Why This Is Dangerous
At this scale, the danger is less about any one account and more about the sheer number of working logins now available to attackers in one place. Every record includes the exact password in plaintext, so there is no cracking or guessing required. An attacker with basic scripting skills can automatically test all 2,668,775 email and password pairs against major websites in a matter of hours.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each account
Why This Matters
A combolist of this size dramatically increases the odds that your information is included, and it makes automated credential stuffing attacks far more efficient for criminals. If your email and password combination is in this file and you have reused that password anywhere else, attackers can pivot into your email, banking, or social media accounts. From there, the path to identity theft and financial fraud is short.
How Large Combolists Like ARCEUSULP Are Built
Combolists are usually assembled by combining data from multiple smaller breaches, phishing campaigns, and stealer logs into one master file. Criminals merge these smaller sources together, remove duplicates, and repackage the result under a new name, in this case ARCEUSULP, before distributing it through Telegram channels and dark web forums. The bigger the combolist, the more valuable it becomes to buyers running large scale credential stuffing operations.
Check If You Are Affected
With millions of records in circulation, checking whether you are affected takes only a few seconds. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including large combolists like ARCEUSULP, so you can confirm your exposure and update your passwords before attackers get there first.
Breach Breakdown
2,668,775 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds