Check Your Inbox: the att Combolist Exposed 40,059 Login Pairs
What HEROIC Analysts Found in the att Combolist: HEROIC analysts identified a combolist labeled "att" that surfaced on Telegram, with data dated to January 2023. The file contains 40,059 records, each combining an email address, a plaintext password, and a URL tied to the account. Why the att Leak Is Dangerous: Since the passwords in this file are stored in plaintext, they can be used the moment someone opens the file. No decryption or cracking is needed, which makes a list of this size immediately usable for large-scale automated login attempts. What Was Exposed: This leak includes email addresses, plaintext passwords, and URLs linked to the associated accounts. Why This Matters: With over 40,000 records, this combolist gives attackers meaningful scale for credential stuffing, testing each email and password pair against other popular sites and services. Anyone in this file who reused their password is at risk of having other accounts, including email, banking, or shopping accounts, taken over using the same login details. How Combolists Work: A combolist is a compiled file of stolen email and password pairs, typically pulled together from a mix of older breaches and phishing hauls, then shared or sold as a single package. Files like this one labeled att often circulate on Telegram channels dedicated to trading leaked credentials. Check If You Are Affected: If you want to know whether your email and password appear in this leak or any other, HEROIC's free breach scanner searches a database of more than 400 billion exposed records, so you can check in seconds and update any passwords you have reused.
Breach Breakdown
40,059 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds