The Dark GhostHex1 Dump Put 2.2 Million Email Logins at Risk
On 4 August 2026, HEROIC analysts tracked a combolist named "Dark GhostHex1 United Kingdom" shared on Telegram. This is a large file, containing 2,249,835 records pairing email addresses with plaintext passwords and the URLs of the accounts they open.
Why This Is Dangerous
At more than 2.2 million entries, this combolist gives attackers enough volume to run large-scale automated login attempts across email providers, banks, and shopping sites. Every password is stored as plain, readable text, meaning no cracking is needed before the credentials can be used.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs identifying the account each credential pair belongs to
Why This Matters
A file this size puts a huge number of email logins at risk of credential stuffing, where attackers try each pair against dozens of other popular sites. Anyone among these 2,249,835 accounts who has reused a password elsewhere faces a real chance of having another account taken over as a result.
How Combolists Work
Large combolists like "Dark GhostHex1" are typically built by merging many smaller breaches, phishing hauls, and stealer logs into one master file, sometimes organized or labeled by region as this one is. Once compiled, attackers load the entire list into credential stuffing software that automatically tests every pair against a wide range of websites in a short amount of time.
Check If You Are Affected
Search your email address against HEROIC's database of more than 400 billion leaked records, including the "Dark GhostHex1" combolist, with a free scan, and change any password you may have reused.
Breach Breakdown
2,249,835 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds