Inside the 18-06-26 Combolist: How It Exposed 88,905 Login Pairs
HEROIC analysts identified a combolist file named "18-06-26," matching its upload date of June 18, 2026, on a Telegram channel. The file contains 88,905 records, each combining an email address with a plaintext password and the URL that login was tied to. Why This Is Dangerous: Every record in this file is a ready-to-use login attempt. There is no encryption to break and no guessing required, an attacker only needs to point automated software at the listed URLs and try each email and password pair directly. What Was Exposed: Email addresses. Plaintext passwords. URLs identifying the specific site or service each set of credentials was captured from. Why This Matters: At nearly 89,000 records, this file gives attackers a large enough pool to run wide-scale credential stuffing attacks, testing leaked passwords against banking, email, and shopping sites in bulk. Anyone who reused a password that appears here risks having other, unrelated accounts compromised too. How a Combolist Like This Works: Files named after their upload date, like this one, are typically compiled and released quickly, often pulled together from stealer malware infections or recycled breach data with little curation. The lack of a descriptive name does not reduce the risk, it just means the source is harder to trace. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records. With nearly 89,000 credentials in this file alone, it is worth taking a minute to scan your email and confirm you are not one of them.
Breach Breakdown
88,905 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds