The Escelsa.com.br Leak: 2,315 Email and Password Pairs Surface
In June 2026, HEROIC analysts identified a combolist file uploaded to Telegram containing 2,315 records tied to the escelsa.com.br domain. Each record pairs an email address with a plaintext password and the URL the login was captured from. Why This Is Dangerous: With the passwords stored in plain, unencrypted text, no technical skill is required to use this data. Anyone who has the file can immediately try each email and password pair against other accounts belonging to the same person. What Was Exposed: - Email addresses - Plaintext passwords - URLs linked to each login Why This Matters: A leak of this size is enough to power a targeted credential stuffing run against the people whose accounts appear in it. Because password reuse is common, a single leaked login tied to one domain can expose email, banking, or shopping accounts elsewhere, opening the door to account takeover, identity theft, and financial fraud. How a Combolist Like This Works: This kind of file is compiled from a mix of sources, older breaches, phishing pages, and malware-infected devices, then filtered down to addresses from a single domain before being uploaded or sold on Telegram. Sorting by domain, as was done here with escelsa.com.br, makes the list more useful to attackers who want to target a specific organization's users. Check If You Are Affected: Search your email address in HEROIC's free breach scanner, which checks against more than 400 billion exposed records, including this escelsa.com.br combolist. If you find a match, change that password immediately and anywhere else you have reused it.
Breach Breakdown
2,315 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds