Dark Web Intel: MIXED2 Telegram Dump Exposes 4,191 Logins
4,191 Credentials Surface in the MIXED2 Dark Web Dump. On October 29, 2024, a Telegram user uploaded a combolist file named MIXED2. HEROIC's dark web intelligence team identified and verified the listing on July 31, 2026, confirming it contains 4,191 records of email addresses, plaintext passwords, and associated URLs. Why This Is Dangerous. The plaintext passwords in this dump can be used immediately, with no cracking required, and the paired URLs tell an attacker exactly which site each login unlocks. That combination makes it simple to automate large numbers of login attempts in a short amount of time. What Was Exposed: Email addresses. Plaintext passwords. Associated login URLs. Why This Matters. Dumps like MIXED2 typically circulate quietly among threat actors before wider distribution, and once in the open, they get fed into credential stuffing tools that test every pair against major websites. Anyone who reused a password from this list on another account faces a real risk of account takeover, identity theft, or financial fraud. How Combolists Work. A combolist bundles email addresses or usernames with matching passwords into a single file, usually sourced from older breaches, phishing pages, or malware infections. Threat actors trade files like MIXED2 across Telegram channels and dark web forums because they require no special tools to use, just a list and a target to test it against. Check If You Are Affected. HEROIC's free breach scanner checks your email address against more than 400 billion leaked records pulled from the dark web, including dumps like MIXED2. Run a free scan now to see if your credentials were exposed.
Breach Breakdown
4,191 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds