What Attackers Can Do With the 852,425-Record EDU Fresh 100 Leak
The "EDU Fresh 100" Combolist: 852,425 Records, Not 1.1 Million
HEROIC analysts identified a combolist file labeled "COMBOLIST 1.1M EDU FRESH 100," uploaded to a Telegram channel and dated November 12, 2025. Despite the "1.1M" in its name, HEROIC's analysis confirms the file actually contains 852,425 records, each pairing an email address with a plaintext password and a matching URL. The "EDU" in the name and the file's education-focused labeling suggest it was compiled around academic email accounts.
Why This Is Dangerous
Because the passwords in this file are plaintext and paired with direct login URLs, an attacker does not need to crack or guess anything. They can attempt to sign in immediately. A list labeled "fresh" also signals the credentials were recently harvested, which means a higher percentage of them are still active and usable than in an older, stale dump.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs linked to the accounts
Why This Matters
At 852,425 records, this combolist is large enough to power serious credential-stuffing campaigns. Attackers run automated tools that test each email and password pair against banking sites, email providers, and other platforms, hoping the same password was reused. Academic email accounts are frequently tied to campus portals, financial aid systems, and cloud storage, which raises the stakes for identity theft and financial fraud if a student or staff credential is reused elsewhere.
How "Fresh" EDU Combolists Are Assembled
A combolist is a plain-text file of "combo" entries, an email or username paired with a password. Lists focused on ".edu" or academic domains are typically built by combining older breach data, phishing campaigns targeting students and staff, or malware infections on campus and personal devices, then labeled by target and freshness before being distributed on Telegram channels and dark web forums.
Check If You Are Affected
If you use an academic email address or have ever reused a password across accounts, it is worth checking your exposure. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including large combolists like this 852,425-record file, so you can find out if your information is circulating and update your credentials before someone else does.
Breach Breakdown
852,425 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds