Good_WordPress Leak: 96 Logins Now Sitting on the Dark Web
In February 2026, HEROIC analysts found a combolist called "Good_WordPress" after a Telegram user uploaded it to a sharing channel. The file contains 96 records of email addresses, plaintext passwords, and the login URLs tied to each account. Why This Is Dangerous: The name suggests these credentials were verified against WordPress-powered login pages, meaning whoever compiled the list confirmed the passwords actually worked on those sites before uploading it. That verification step is what separates a good list from an unverified one in combolist marketplaces, and it makes these 96 accounts more immediately useful to an attacker. What Was Exposed: Email addresses. Plaintext passwords. Associated login URLs. Why This Matters: An unverified combolist might be full of dead logins, but a file labeled good implies someone already tested it. If your login is one of the 96 in this file, an attacker is not guessing, they already know the password works, and they can use it to take over a website login, a WordPress admin panel, or anything else protected by that same password. How This Combolist Was Likely Built: Compilers run raw stolen credentials through automated tools that attempt to log into the target platform, in this case WordPress sites, and keep only the pairs that succeed. The result is a smaller but far more dangerous file, since every entry has already been confirmed to work. Check If You Were Affected: A short list does not mean low risk when the credentials have already been verified. HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this file, so you can confirm your exposure and change your password before it is used.
Breach Breakdown
96 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds