The FR Telegram Dump Has Just 12 Logins, But Check Yours Anyway
In June 2026, HEROIC analysts found a tiny combolist simply named "FR" after a Telegram user uploaded it to a sharing channel. The file contains just 12 records of email addresses, plaintext passwords, and the login URLs tied to each account. Why This Is Dangerous: Twelve records is about as small as a leak gets, and it is tempting to dismiss a file this size as insignificant, but each row represents a real person's working email and password. If you are one of the 12, the size of the file does nothing to reduce the risk to your account. What Was Exposed: Email addresses. Plaintext passwords. Associated login URLs. Why This Matters: Attackers do not need a massive file to cause damage. A list of even a dozen working logins is enough to attempt credential stuffing against banking, email, or shopping accounts, and because the passwords are plaintext, no cracking or guessing is required to try them. How This Combolist Was Likely Built: Small files like this often come from a single phishing page, a short-lived malware infection, or a leftover fragment of a larger breach that got split apart and uploaded separately. They are usually shared for free to build a reputation on a Telegram channel before a bigger, paid list is advertised. Check If You Were Affected: A small file is still worth checking. HEROIC's free breach scanner compares your email address against more than 400 billion leaked records, including tiny dumps like this one, so you know for certain rather than assuming you are safe because the leak was small.
Breach Breakdown
12 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds