The IN Combo Leaked in June. Its 3 Records Just Surfaced Online.
HEROIC analysts identified a small combolist labeled "IN" that was uploaded to a Telegram channel on 18 June 2026. The file contains just 3 records, each made up of an email address, a plaintext password, and the login URL that credential belongs to.
Why This Is Dangerous
A small file is not a safe file. Each of these 3 records pairs a working email address with a plaintext password and the exact site it unlocks, meaning anyone who picks up this list can attempt to log in immediately, with no cracking required.
What Was Exposed
- Email addresses
- Plaintext passwords
- Login URLs for the associated accounts
Why This Matters
Even a handful of exposed credentials can lead to full account takeover if the password is reused elsewhere. Attackers often plug small combolists like this one straight into automated tools that try each pair against other popular sites, a tactic known as credential stuffing. For the people behind these 3 records, the risk is just as real as it would be in a much larger leak.
How Combolists Work
A combolist is a plain text file pairing usernames or email addresses with passwords, usually pulled together from older leaks or stealer logs rather than stolen from one single company. Even small batches like this one get uploaded to Telegram channels, where they sit until someone downloads them and starts testing the credentials against real websites.
Check If You Are Affected
To check whether your email address or passwords appear in this combolist or any other leak, HEROIC's free breach scanner searches a database of more than 400 billion leaked records in just a few seconds.
Breach Breakdown
3 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds