How a Telegram Combolist Leak Exposed 993 icloud.com Logins
On August 2, 2026, HEROIC analysts found a combolist labeled icloud.com, uploaded to a Telegram channel by an anonymous user. The file contains 993 records pairing email addresses with plaintext passwords and the URLs of the accounts they access.
How This icloud.com Leak Happened
This file didn't come from a hack of Apple's systems. Combolists like this one are built by criminals who pull email and password pairs from older, unrelated breaches and malware logs, then filter the results down to whichever email domain they're interested in, in this case, icloud.com addresses. The 993 credentials here were compiled and shared specifically because they belong to Apple account holders, then uploaded to Telegram for other criminals to use.
What Was Exposed in the icloud.com Leak
- Email addresses
- Plaintext passwords
- URLs linking each credential to its source site
Why This Matters
An Apple ID often controls far more than email: it can be tied to iCloud backups, Find My iPhone, payment methods, and app purchases. If someone's icloud.com login was reused elsewhere and now sits in this combolist, they face a real risk of account takeover, financial fraud, or identity theft, depending on what else that email and password combination unlocks.
Check If You Are Affected
If you use an icloud.com email address, it's worth checking whether it appears in this leak or any other breach. HEROIC's free breach scanner searches a database of more than 400 billion leaked records in seconds, giving you an early warning to change your password.
Breach Breakdown
993 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds