ArtHouse Combolist Breach: 12.4M Plaintext Passwords Since July
ArtHouse Combolist: 12.4 Million Credentials Exposed
In July 2026, HEROIC analysts identified a large combolist, dubbed "ArtHouse," uploaded to a Telegram channel by an anonymous user. The file contained 12,428,981 individual records pairing email addresses with plaintext passwords, along with the URLs of the sites those credentials were originally used on. Because the passwords were stored in plaintext rather than hashed or encrypted, anyone who obtains this file can use the credentials immediately, with no cracking required.
Why This Is Dangerous
A combolist like this hands attackers a ready-to-use list of working logins. Because the file also includes the URL each credential pair was tied to, criminals do not have to guess where to try a password. They already know which site to target, which makes automated login attempts far more efficient and far more likely to succeed.
If you reused a password from this list on any other account, banking, email, shopping, or social media, that account is at immediate risk. Attackers routinely feed combolists like this into automated tools that test the same email and password combination across hundreds of popular websites in seconds.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the associated accounts
Why This Matters
Combolists are the raw fuel behind credential stuffing attacks. Because plaintext passwords require no extra effort to use, this data can be weaponized instantly against any account where the same email and password combination is still active. If the password was reused anywhere else, that account is exposed to account takeover, unauthorized purchases, or identity theft. Once inside an email or financial account, attackers can pivot further, resetting other passwords, draining funds, or impersonating the victim to commit fraud.
How a Combolist Attack Works
A combolist is simply a compiled file of email (or username) and password pairs, often assembled by scraping older breaches, malware logs, or leaked databases and merging them into one large file. Unlike a single-source breach, combolists are built for volume and reuse. Criminals load these files into credential stuffing tools that automatically try each pair against dozens of websites and apps, banking on the fact that many people reuse the same password across multiple accounts. Because the ArtHouse list stored passwords in plaintext, there is no encryption to break through, making the credentials usable the moment the file changes hands.
Check If You Are Affected
If your email address might be part of this or any other leaked dataset, it is worth finding out before an attacker does. HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including combolists like this one, and tells you immediately if your information has been exposed. Run a free scan now and, if you find a match, change the affected password right away and avoid reusing it anywhere else.
Breach Breakdown
12,428,981 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds