The Finland Corp Mail Dump Gave Hackers What They Need to Log In
HEROIC analysts reviewed a combolist labeled "FINLAND CORP-OTHERS-PRO MAILS TEST SAMPLE," uploaded to Telegram in February 2026. The file contains 1,052 records pairing corporate and other email addresses, apparently tied to Finnish organizations, with plaintext passwords and login URLs.
Why This Is Dangerous
The word "sample" in this file's name is a red flag by itself. Sellers often release a small preview of a larger batch to prove the data works before selling the full set. That means the 1,052 records here could be a fraction of a much bigger pool of stolen corporate email credentials being offered elsewhere.
What Was Exposed
- Corporate and other email addresses
- Plaintext passwords
- Associated login URLs
Why This Matters
A working email and password pair from a corporate inbox gives an attacker everything needed to log in directly, no cracking, no guessing. From there, business email compromise, invoice fraud, and further phishing against coworkers and clients all become possible, especially if the compromised account belongs to someone in finance or leadership.
How Combolists Work
Combolists like this "test sample" are typically assembled from a mix of sources, older leaks, stealer logs, and phishing hauls, then organized around a theme, here, Finnish corporate and miscellaneous professional mail accounts. Labeling a portion as a "sample" is a common sales tactic used to build buyer confidence before a larger transaction.
Check If You Are Affected
Search your email address using HEROIC's free breach scanner, which checks against more than 400 billion leaked records, to see if your account is part of this sample or any related exposure.
Breach Breakdown
1,052 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds