Identity Theft Risk Climbs After the Mixed Valids Combolist Leak
In January 2025, HEROIC analysts found a combolist labeled "Mixed valids" uploaded to Telegram. The file contains 2,433 records of email addresses paired with plaintext passwords and the URLs where each pair was confirmed to work, meaning the credentials had already been checked and validated before the file was shared.
Why This Is Dangerous
A "valids" list is more dangerous than a raw, unfiltered combolist because someone has already tested each login and removed the dead entries. That means every one of the 2,433 records in this file is more likely to still work, giving whoever downloads it a higher success rate for breaking into accounts.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs confirming where each login was validated
Why This Matters
Because these credentials were pre-verified, they carry a real risk of identity theft and account takeover for anyone included. If a password from this list was reused across other accounts, an attacker can use credential stuffing to break into email, financial, or shopping accounts far beyond the original site.
How Combolists Get Marked "Valid"
Criminals often run large, unfiltered combolists through automated login-checking tools called checkers or crackers. Any pair that successfully logs in gets tagged as "valid" and moved into a smaller, higher-quality file, exactly what appears to have happened with this "Mixed valids" upload before it was shared on Telegram.
Check If You Are Affected
Search HEROIC's free breach scanner, which checks your email against more than 400 billion leaked records, to see if your credentials appear in this or any other exposure. If they do, change that password everywhere you have used it.
Breach Breakdown
2,433 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds