Dark Web Intel: 939,969 Credentials From the ARCEUSULP Combo
HEROIC analysts identified a combolist labeled "ARCEUSULP 128 2361700" that was uploaded to a Telegram channel on 20 June 2026. The file contains 939,969 records made up of email addresses, plaintext passwords, and the login URLs those credentials belong to.
Why This Is Dangerous
At nearly a million records, this is one of the larger combolists HEROIC analysts have tracked recently. Each entry pairs a working email address with a plaintext password and the exact web address it logs into, meaning an attacker can start testing accounts immediately with no cracking required.
What Was Exposed
- Email addresses
- Plaintext passwords
- Login URLs for the associated accounts
Why This Matters
With 939,969 records in a single file, this combolist gives attackers a huge pool of accounts to run through credential stuffing tools, automatically testing each email and password pair against banking sites, email providers, and social media. Anyone whose credentials appear here faces a real risk of account takeover, especially if the password has been reused elsewhere.
How Combolists Work
A combolist pairs usernames or email addresses with passwords, one credential set per line, typically assembled by combining data from older leaks and stealer logs rather than a single company's breach. Large files like this one circulate through Telegram channels and dark web forums, where other users download them and test the credentials at scale against real login pages.
Check If You Are Affected
To find out whether your email address or passwords appear in this combolist or any other leak, HEROIC's free breach scanner checks your information against a database of more than 400 billion leaked records in just a few seconds.
Breach Breakdown
939,969 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds