The Colombia 4 Combolist Holds 2,204 Real Login Credentials
In August 2022, HEROIC analysts identified a combolist titled "Colombia 4" uploaded to a Telegram channel by an anonymous user. The file contained 2,204 records pairing email addresses with plaintext passwords and associated URLs. Why the Colombia 4 Combolist Is Dangerous: because every password in this file is stored in plain, readable text, an attacker does not need any special tools or technical skill to use the credentials, they simply copy and paste them into a login page. What Was Exposed: email addresses, plaintext passwords, and the URLs tied to each login. Why This Matters: 2,204 people having their login pairs exposed means real risk of account takeover, especially for anyone who reused the same password across multiple sites. Attackers routinely run leaked credentials like these against banking portals, email providers, and online stores, hoping to find a match that still works. How a Combolist Works: a combolist is built by combining email or username and password pairs from a variety of sources, such as older breaches, phishing pages, and malware infections, into a single file. Criminals then run that file through automated tools that attempt each login across many websites at once, a technique known as credential stuffing. The Colombia 4 combolist follows this same pattern, bundling 2,204 email and password combinations with the URLs they were paired to. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including combolists like Colombia 4. Run a free scan today to see if your credentials have been exposed.
Breach Breakdown
2,204 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds