Argentina 6: A Telegram Combolist Exposing 10,107 Login Pairs
In February 2023, HEROIC analysts found a combolist named "Argentina 6" after a Telegram user uploaded it to a file-sharing group. The file contains 10,107 records of email addresses, plaintext passwords, and the login URLs tied to each account. Why This Is Dangerous: Unlike a generic mixed combolist, the name suggests the compiler grouped these stolen credentials around a shared regional theme, which makes it easier for buyers to run localized fraud or phishing campaigns using all 10,107 accounts at once. What Was Exposed: Email addresses. Plaintext passwords. Associated login URLs. Why This Matters: A regionally grouped combolist can be more dangerous than a random mix, because an attacker can target one set of banks, retailers, or services with the entire file instead of guessing where each login might work. If your email is in this file, an attacker already has a starting password and a good idea of which services you are likely to use. How This Combolist Was Likely Built: Compilers often sort stolen credentials by domain, language, or region before packaging them, and label the file to reflect that focus. The underlying data still comes from the same mix of older breaches and stealer logs as any other combolist, sorting it this way just makes the list more valuable to a specific buyer. Check If You Were Affected: HEROIC's free breach scanner checks your address against more than 400 billion leaked records, including this combolist, so you can find out in seconds and secure your account before it is misused.
Breach Breakdown
10,107 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds