Dark Web Intel: Yahoo New Part 54 Combolist Exposes 2.6M Credentials
HEROIC analysts uncovered a combolist named "YAHOO NEW PART 54" circulating on a Telegram channel, dated April 24, 2023. The file contains 2,602,151 records, each pairing an email address with a plaintext password and the URL the login was used on, with the naming suggesting it is one installment in a much larger series of similar files. Why This Is Dangerous: At over 2.6 million records, this is not a small, isolated leak. It is a large, ready-to-use list of working email and password combinations that can be fed directly into automated login tools, no cracking or decryption required. What Was Exposed: Email addresses, with a focus on Yahoo and related accounts based on the file's naming. Plaintext passwords. URLs identifying the login pages tied to each credential pair. Why This Matters: A compromised Yahoo account is frequently used as a recovery email for other services, meaning attackers who gain access can pivot from one email inbox into banking apps, social media, and shopping accounts. With millions of records in a single file, even a modest reuse rate translates into a large number of real account takeovers. How a Combolist Like This Works: The "PART 54" in the filename points to an ongoing series, where an uploader repeatedly compiles and releases large batches of Yahoo-related credentials sourced from stealer malware and older breaches, distributing them piece by piece across Telegram to keep demand steady. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records. If you use Yahoo Mail or have used it as a recovery address, run a scan now to see if your credentials are part of this multi-million record dump.
Breach Breakdown
2,602,151 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds