cbanke Combolist Leaked: 200 Plaintext Passwords Live On
HEROIC analysts catalogued a cbanke combolist file dated June 7, 2020 holding 200 lines of email addresses, plaintext passwords, and the URL each pair was collected from. It is the smallest file HEROIC has logged from this particular batch of uploads. Small does not mean harmless, and the file is already circulating.
Why Even a Short File Is Dangerous
A file with only 200 entries is trivial for an attacker to run through automated login tools in seconds, testing every pair against the tagged site and a short list of common services. There is no volume threshold that makes a working credential safe to ignore.
What Was Exposed
- Email addresses: identifies the account holder and points to related accounts worth checking.
- Plaintext passwords: usable immediately, with no cracking step in the way.
- URLs: confirms the exact site each password pair is known to work on.
What Being in This File Could Cost You
A match here puts the tagged account at direct risk of takeover, and if that account is your email, it can be used to reset other services connected to it. A short file simply means fewer people are affected, not that the impact on each one is any smaller.
How Files Like This Are Assembled
This is a combolist, compiled from older leaks and malware-collected logins rather than one company's systems, then organized by the site each credential pair worked on before being shared through the same channel.
Check the File Before Someone Else Uses It
Scan your email to see if your address is one of the 200 in this file. If it is, change that password right away and avoid reusing it anywhere else, including on any account you access through a work email.
Breach Breakdown
200 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds