The ‘de’ File: 7,189,280 Emails and Passwords Leaked Online
HEROIC analysts found a combolist labeled 'de' circulating on Telegram, dated February 20, 2024. It held 7,189,280 email and password pairs with matching login URLs. If you've reused a password across more than one site in the past couple of years, this file is worth checking against your own inbox right now using the tool below.
What an Attacker Could Actually Do With This File
Every row in this combolist is a ready-to-use login: an email address, its plaintext password, and the web address where that password worked. There is no cracking step and no guesswork involved. Anyone who downloads the file can plug the pairs directly into automated login tools and test them against banking portals, email providers, and shopping accounts within minutes.
What Was Inside the File
- Email addresses: usable as a username on most sites and a direct channel for follow-up phishing.
- Plaintext passwords: readable and usable immediately, no decryption needed.
- URLs: the exact site each login pair was captured from, letting an attacker target the right service straight away.
The Real Risk of Reused Passwords
Because these pairs are already matched to specific sites, the main danger is credential stuffing: attackers feed the list into a script that tries each email and password on dozens of other popular services. Anyone who reused one of these passwords elsewhere, especially on email or financial accounts, is exposed to account takeover the moment the file starts circulating.
How a Combolist Like This Comes Together
A combolist is not a hack of one company. It is a compilation, usually stitched together from older breaches and stealer malware output, then repackaged and shared on Telegram under a short, often meaningless label like 'de'. The name itself carries no information about who is affected; only the data inside does.
Is Your Email Part of the 'de' Leak?
Start by running your address through HEROIC's scan your email tool to see if it turns up in this file or any other leak in our records. If it does, change the password on that account immediately, and change it anywhere else you used the same one, starting with your email and banking logins since those give an attacker the most leverage. Give each account its own unique password going forward. This check matters whether the address is one you use for work or personal accounts, since both show up in combolists like this one just as often.
Breach Breakdown
7,189,280 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds