Identity Theft Risk Grows After 874 AUT.ac.nz Emails Leak Online
HEROIC analysts found a combolist titled "aut.ac.nz - 874 emails" uploaded to a Telegram channel on June 10, 2026. The file contains 874 records, each pairing an email address tied to the aut.ac.nz domain, used by Auckland University of Technology, with a plaintext password and the URL the login was used on. Why This Is Dangerous: University email accounts are often used as a trusted identity across many other services, from banking to job applications to personal email recovery. A working password tied to one of these accounts can let an attacker impersonate a student or staff member well beyond the university's own systems. What Was Exposed: Email addresses on the aut.ac.nz domain. Plaintext passwords. URLs indicating where each login was captured. Why This Matters: If someone in this file reused their university password on a personal account, an attacker now has a direct route into both their academic records and their personal life, opening the door to identity theft, financial fraud, or further account takeover using the university email as a recovery point. How a Combolist Like This Gets Made: Domain-specific lists like this one are typically pulled together from phishing campaigns targeting a single organization or from stealer malware installed on students' or staff members' personal devices, then packaged around the domain name to signal exactly who the data belongs to. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records. If you have an aut.ac.nz email address, run a scan now to see if your credentials are part of this 874-record leak.
Breach Breakdown
874 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds