The “Good” Combolist Resurfaces With Another 601 Stolen Logins
What HEROIC Analysts Found in This Second "Good" Combolist Leak
In December 2025, HEROIC analysts identified another combolist labeled "good," uploaded to a Telegram channel by an anonymous user. This file, separate from an earlier "good" list HEROIC also tracked, contained 601 records of email addresses paired with plaintext passwords and the URLs those credentials were used on.
Why This Is Dangerous
Even at a smaller scale, this file carries the same risk as any other plaintext combolist: paired with a matching site URL, the credentials inside are ready for an attacker to use the moment the file is downloaded, with no extra cracking or guessing required.
What Was Exposed in This "Good" Combolist
- Email addresses
- Plaintext passwords
- URLs of the associated websites
Why This Matters for the 601 Affected Accounts
A smaller file does not mean smaller consequences for the people in it. Anyone among the 601 affected accounts who reused a password on another site is at real risk of credential stuffing, account takeover, or financial fraud.
How Repeated "Good" Combolists Keep Appearing
Compilers frequently reuse simple, generic labels like "good" across multiple separate files, drawn from different batches of older breaches and stealer malware logs, and release them at different times through the same Telegram channels.
Check If You Are Affected
To find out if your email address is part of this or any other leak, run a free scan with HEROIC's breach scanner, which checks against more than 400 billion leaked records, and get clear steps to secure your accounts.
Breach Breakdown
601 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds