Inside the Centrin.net.id Combolist: 3,137 Accounts Leaked
On June 10, 2026, HEROIC analysts discovered a combolist uploaded to Telegram containing 3,137 records tied to Centrin.net.id, an Indonesian internet service provider. Each record included an email address, a plaintext password, and the URL the login was tied to. Why This Is Dangerous: Storing passwords in plaintext means the file requires no cracking or decryption, so anyone who downloads it can pair each password with its matching email address to attempt a direct login or test the combination against other accounts. What Was Exposed: The file contains email addresses, plaintext passwords, and the URLs tied to each login. Why This Matters: Even a few thousand accounts can cause real harm if the passwords inside are reused elsewhere. Attackers feed lists like this into automated credential stuffing tools that try the same login across banking, email, and shopping sites, and a successful match can lead to account takeover, identity theft, or fraud. How This Combolist Was Likely Built: This type of file is typically compiled from older leaks, phishing campaigns, or infected devices, then filtered down to a specific domain, here Centrin.net.id, before being shared on Telegram. Check If You're Affected: If you use a Centrin.net.id email address or reuse passwords across accounts, HEROIC's free breach scanner searches over 400 billion leaked records so you can update any at-risk passwords before someone else does.
Breach Breakdown
3,137 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds