Webmail Accounts Exposed in the ig.com.br Combolist: 300 Logins Leaked
HEROIC analysts identified a combolist titled "300 .ig com br Mail Access," uploaded to a Telegram channel on April 7, 2026. The file contains 300 records of email addresses, plaintext passwords, and login URLs tied to ig.com.br webmail accounts.
Why This Is Dangerous
Because this list is built specifically around ig.com.br webmail logins, an attacker already knows exactly which service each credential belongs to. Paired with a plaintext password and login URL, that focus lets an attacker move straight to signing in, rather than guessing where stolen credentials might work.
What Was Exposed
- Email addresses
- Plaintext passwords
- Webmail login URLs
Why This Matters
Email accounts are often the key to resetting passwords on other services, so a compromised webmail login can quickly become a way into banking, shopping, and social media accounts linked to that inbox. A targeted list like this one makes that kind of follow-on attack easier to carry out.
How Combolists Work
A combolist pairs emails or usernames with passwords, usually gathered from earlier leaks or malware infections, then compiled into a file and shared on platforms like Telegram. Lists focused on a single email provider, as this one is, are typically curated by filtering a larger leak down to just the accounts an attacker cares about.
Check If You Are Affected
HEROIC's database holds more than 400 billion records from combolists, stealer logs, and confirmed breaches. Run a free scan to check if your email appears in this ig.com.br mail access dump or any other exposure, and see how to secure your account.
Breach Breakdown
300 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds