Inside 140K China Combolist: 88,015 Passwords Harvested
HEROIC analysts uncovered a massive stealer log dump titled "140K CHINA Good Quality Combolist" on Telegram in June 2026. Despite the title claiming 140,000 records, the actual file contained 88,015 compromised credentials specifically targeting Chinese internet users. Each entry includes an email address, a plaintext password, and the URL of the compromised service. The "Good Quality" designation indicates the operator has filtered or validated these credentials to ensure a higher rate of working logins.
Why 88,015 Plaintext Chinese Credentials Create Massive Exposure
China has one of the world's largest internet populations, and the exposure of 88,015 credentials in plaintext creates an enormous attack surface. These passwords can be used immediately against Chinese email services, e-commerce platforms, social media accounts, and corporate systems without any decryption or cracking required.
Chinese internet users often maintain accounts across platforms like QQ, WeChat, Taobao, Alipay, and Baidu, many of which are interconnected. A single compromised credential can provide access to payment systems, messaging platforms, and cloud storage services that contain sensitive personal and financial data.
The "Good Quality" label suggests these credentials have been cleaned or validated to remove duplicates and dead entries. This curation makes the dump more valuable to attackers and more dangerous to victims, as a higher percentage of the entries are expected to grant successful access.
What Was Exposed in the 140K China Combolist
- Email Addresses — Chinese email addresses from major providers and organizational domains
- Plaintext Passwords — Unencrypted passwords harvested from Chinese users' devices
- URLs — Login pages for Chinese and international services used by the victims
Why This Volume of Chinese Data Enables Industrial-Scale Fraud
With 88,015 credentials, attackers can execute massive credential stuffing campaigns against Chinese platforms. The interconnected nature of Chinese digital ecosystems means that a password working on one platform often grants access to linked payment services, messaging apps, and cloud accounts.
Chinese credentials are particularly valuable for financial fraud. Access to Alipay, WeChat Pay, and Chinese banking portals can enable direct monetary theft. Even non-financial accounts can be monetized through identity theft, account resale, or leveraging stored payment methods for unauthorized purchases.
The scale of this dump also supports social engineering campaigns targeting Chinese businesses. Compromised corporate email accounts can be used for business email compromise attacks, fake invoice fraud, and supply chain manipulation within the Chinese market.
How Stealer Logs Harvest Chinese User Credentials
Infostealer malware targeting Chinese users is distributed through localized attack vectors including fake software downloads on Chinese file-sharing platforms, phishing campaigns via QQ and WeChat, and compromised Chinese websites serving malicious payloads. Malware variants like RedLine, Raccoon, and region-specific stealers are commonly deployed.
Once installed, the malware extracts saved credentials from browsers popular in China, including Chrome, Edge, and 360 Browser, as well as from desktop applications and messaging clients. The harvested data is then transmitted to attacker servers for processing and organization.
The operator behind this dump invested additional effort in quality control, filtering the raw stealer log output to create a curated combolist. This post-processing step removes invalid entries and organizes the data for maximum exploitation efficiency, which is why the final count of 88,015 differs from the advertised 140,000.
Check If Your Credentials Were Exposed
If you use Chinese internet services or maintain accounts on Chinese platforms, your credentials could be among the 88,015 records in this combolist. The curated nature of this dump means the included credentials are more likely to be current and working, making immediate password changes critical.
Use the HEROIC data breach scanner to search across more than 400 billion compromised records. Verify whether your email address appeared in this China-targeted combolist or any other known breach, and enable multi-factor authentication on all accounts, especially those connected to financial services.
Breach Breakdown
88,015 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds