How a Telegram Upload Exposed 88,558 Brazilian Domain Logins
A Telegram upload exposed 88,558 records in a combolist named "107K Brazilian BR Domain base," shared in April 2023. The list, self-labeled as focused on .br domain accounts, pairs email addresses with plaintext passwords and the URLs each login was tied to.
Why This Is Dangerous
Domain-focused combolists like this one are built around a shared theme, in this case accounts tied to Brazilian web domains, which makes them attractive to attackers who want to target a specific region or language for follow-up phishing or fraud rather than testing accounts at random.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs linked to each login
Why This Matters
With 88,558 records involved, anyone whose credentials appear here faces the risk of account takeover, and reused passwords open the door to credential stuffing across other services. Grouping by domain also makes it easier for attackers to craft convincing, localized phishing emails aimed at the people on this list.
How a Domain-Themed Combolist Is Assembled
To build a list like this, criminals filter a larger pool of stolen credentials down to accounts registered on a specific domain suffix, in this case ".br," combining data from phishing pages, stealer malware, and older breaches before packaging and sharing the themed file on Telegram.
Check If You Are Affected
Search HEROIC's free breach scanner, which checks your email against more than 400 billion leaked records, to see if you are among the 88,558 accounts in this file, and change your password if you find a match.
Breach Breakdown
88,558 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds