Dark Web Intel: 32 Credentials From the hits_imap Combolist
On 4 August 2026, HEROIC analysts tracked a small combolist named "hits_imap" uploaded to a Telegram channel used to distribute stolen credentials. The file contains 32 records pairing email addresses with plaintext passwords and the URLs of the accounts they unlock.
Why This Is Dangerous
The name "hits_imap" points to email accounts accessed through IMAP, the protocol many email apps use to sync your inbox. Because the passwords here are stored in plaintext, an attacker with this file could connect directly to those mailboxes and read, send, or forward email without the account owner ever noticing a login page.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs identifying the account each credential pair belongs to
Why This Matters
IMAP access effectively hands over the mailbox itself, letting an attacker quietly monitor incoming password reset emails, invoices, or personal messages. Even with only 32 accounts affected, each one is a direct route into whatever other services that email address controls.
How Combolists Work
Combolists focused on IMAP, like "hits_imap," are built from email-and-password pairs specifically confirmed to work through direct mail protocol connections rather than a website login page. This makes them attractive to attackers who want to quietly read a victim's email over time instead of triggering the alerts a normal web login might cause.
Check If You Are Affected
Search your email address against HEROIC's database of more than 400 billion leaked records with a free scan to see if it appears in the "hits_imap" combolist or any other exposure.
Breach Breakdown
32 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds