Inside the KurdishPy Combolist: How 4,336 French Logins Leaked
HEROIC analysts identified a combolist labeled 4.3K_France_KurdishPy, uploaded by a Telegram user on July 28, 2026. The file contains 4,336 records of French email addresses paired with plaintext passwords and the URLs those credentials unlock. Why this is dangerous: the name of this file tells its own story. It signals a batch of roughly 4,300 French accounts, compiled and labeled by whoever put it together before sharing it on Telegram. That kind of packaging means the data has already been sorted and is ready for immediate use in automated login attempts. What was exposed: French email addresses, plaintext passwords, and the URLs tied to each set of credentials. Why this matters: once a combolist like this circulates, anyone can download it and start testing the credentials against banking, email, and shopping sites through credential stuffing tools. If a password was reused anywhere else, the fallout can spread quickly into account takeover, identity theft, and financial fraud. How combolists work: a combolist is created by pulling email and password pairs from older breaches, stealer malware infections, or phishing campaigns, then combining and labeling them, often by country or size, as seen in this file's name. Once packaged, the list gets shared or sold on platforms like Telegram, where other criminals pick it up and run it through automated tools to find accounts where the password still works. Check if you are affected: HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including combolists like this one. Run a scan to see if your account was part of this exposure and learn which passwords to change.
Breach Breakdown
4,336 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds