The Aruba.it Test List Leaked 1,001 Working Logins on Telegram
What HEROIC Analysts Found On 11 January 2026, HEROIC analysts found a combolist labeled Aruba.it test uploaded to Telegram. It contains 1,001 records, each pairing an email address with a plaintext password and a related URL. Why This Is Dangerous The word test in the file name does not make the data any less real. Each of these 1,001 entries includes a working, readable password that an attacker can use right away, no extra effort required to unlock the account it belongs to. What Was Exposed 1,001 email addresses Plaintext passwords for each account URLs tied to each login Why This Matters Combolists like this one get run through automated tools that test each email and password pair against popular websites, a technique called credential stuffing. Anyone in this batch who reused their password on another site risks having that account taken over too, which can quickly lead to identity theft or financial fraud. How a Test Combolist Gets Made and Shared Files labeled test are often smaller batches an uploader shares to prove a larger combolist actually works before selling or trading the full version. These lists are typically built from older breaches, phishing pages, or malware logs rather than one single hack, then shared across Telegram channels dedicated to trading credentials. Check If You Are Affected If you think your email might be part of this leak, it is easy to find out for certain. HEROIC's free breach scanner checks your email against more than 400 billion exposed records, giving you a fast answer so you can update your password if it turns up.
Breach Breakdown
1,001 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds