The ‘good’ Leak: 1,425 Passwords Exposed. Yours Could Be One.
In October 2025, HEROIC analysts found a combolist named "good" uploaded by a Telegram user, containing 1,425 records that pair email addresses with plaintext passwords and the URLs they were pulled from.
Why This Is Dangerous
Every password in this file is stored in readable plaintext, meaning anyone who gets a copy of the list can log into the affected accounts right now, without needing to crack or guess anything.
What Was Exposed in the 'good' Leak
- Email addresses
- Plaintext passwords
- Source URLs
Why This Matters
Once a combolist like this is posted, it spreads fast across Telegram channels and forums, where other criminals grab it for their own credential stuffing attacks. If your email and password show up here and you have reused that password anywhere else, the risk extends well beyond the original account.
How a Combolist Attack Works
A combolist bundles stolen email and password pairs from breaches, phishing, or malware into a single downloadable file. Attackers automate the process of testing each pair against major websites, quickly separating working logins from dead ones and reselling or reusing the good hits.
Check If You Are Affected
Do not wait to find out the hard way. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this 'good' combolist, so you can act before an attacker does.
Breach Breakdown
1,425 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds