The Bigger goodFTPs Batch Could Open Servers, Email, and More
This is the larger of two related files circulating under the name goodFTPs, originally dated October 2023 and still being passed around on Telegram. Where the smaller version held 18 records, this one holds 172 email and password pairs tied to FTP server access, every password stored in plain text. The risk here doesn't stop at the server itself, since a reused password can chain into email and other accounts too. Scan your email to see if you're one of the 172.
Why the Risk Doesn't Stop at the Server
An FTP password is often set once and reused elsewhere out of convenience. If that's the case here, a working FTP login could also unlock the email account tied to the same person, and from there, anything that email can reset.
What Was Exposed
- Email addresses: identify the account tied to each of the 172 FTP logins.
- Plaintext passwords: readable and usable immediately, with nothing to crack.
- URLs: point to the exact server each credential connects to.
Where the Chain Can Lead
Starting from a server login, an attacker can pivot to the email account managing that server, then use that inbox to reset passwords on hosting accounts, domain registrars, or anything else tied to it.
How a Batch This Size Gets Assembled
Larger FTP credential files like this one are usually built by combining several smaller captures of server logins, verifying which ones still connect, and releasing the confirmed batch together.
Break the Chain Before It Starts
Scan your email to check the larger goodFTPs batch. If you're listed, change the FTP password now and any account that shares it, starting with email, from a device you trust. This applies to personal projects and work managed servers alike.
Breach Breakdown
172 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds