Search Your Email: COMBOLIST 165K Gmail Leak Exposed 164,796 Logins
HEROIC analysts identified a combolist titled "COMBOLIST 165K GMAIL.COM FRESH 100" circulating on a Telegram channel on 16-Jan-2026. The file contains 164,796 records tied to Gmail.com accounts, including email addresses, plaintext passwords, and the URLs of the sites those logins were captured on. The word "fresh" in the file name is a signal to buyers that the credentials have not been widely resold yet, which makes them more valuable to criminals looking for accounts that still work.
Why This Is Dangerous
Every credential in this file is stored as plaintext, meaning anyone who downloads it can read the password directly with no cracking required. Combined with the matching email address and the URL of the site it was used on, an attacker has everything needed to log straight into an account. If that Gmail address is reused anywhere else, the same password likely unlocks banking, shopping, and social media logins too.
What Was Exposed in the COMBOLIST 165K GMAIL.COM FRESH 100 File
- Email addresses (Gmail.com accounts)
- Plaintext passwords
- URLs of the sites where the credentials were used
Why This Matters for Gmail Users
A combolist this size gives attackers a ready made list to automate. Bots take the email and password pairs and quietly test them against banks, email providers, and online stores in a process known as credential stuffing. Because the passwords are already in plaintext, there is no delay while criminals crack anything, accounts can be accessed within minutes of the list going live. From there, account takeover, identity theft, and financial fraud can follow quickly, especially if the Gmail inbox is used to reset passwords on other services.
How a Combolist Like This Gets Built
A combolist is a compiled file of username or email and password pairs, often stitched together from multiple sources such as older breaches, phishing pages, or malware infections on personal devices. Sellers on Telegram and dark web forums package these lists by domain, in this case Gmail.com, to appeal to buyers who want to target a specific type of account. A "fresh" combolist typically means it was recently assembled and has not yet been filtered out by services that flag known compromised passwords, giving attackers a short window where the credentials are more likely to still be active.
Check If You Are Affected
If you use a Gmail.com address, it is worth checking whether your email shows up in this exposure or in any of the other breaches HEROIC tracks. HEROIC's free breach scanner searches a database of more than 400 billion leaked records to tell you quickly if your information has been exposed, and what to do next to secure your accounts.
Breach Breakdown
164,796 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds