HEROIC Analysts Found the Alexu.edu.eg Leak: 2,928 Accounts Exposed
In June 2026, HEROIC analysts found a combolist file tied to alexu.edu.eg, the domain used by Alexandria University in Egypt, uploaded to a Telegram channel. The file contained 2,928 records pairing university email addresses with plaintext passwords and associated URLs. Why This Is Dangerous: Because the passwords in this file are stored in plaintext, anyone who downloads the file can read and use them right away. University accounts frequently connect to email, course platforms, and sometimes payment systems, giving an attacker several angles of attack from a single working login. What Was Exposed: - University email addresses - Plaintext passwords - URLs linked to each account Why This Matters: Even a smaller list like this one puts real people at risk. If any of these 2,928 students or staff reused their university password on a personal email, banking, or shopping account, an attacker could use credential stuffing to gain access there too, potentially leading to financial fraud or identity theft. How a Combolist Like This Works: Attackers or list compilers commonly filter larger stealer malware dumps or breach collections by domain, pulling out accounts tied to a specific organization like a university to create a smaller, targeted list that is easier to sell or use for phishing. Check If You Are Affected: Use HEROIC's free breach scanner to check your email against more than 400 billion exposed records and see if your credentials appear in this or any other leak.
Breach Breakdown
2,928 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds