Inside ‘ultra uhq priv combs’: 3,458 Stolen Login Pairs Found
In April 2025, HEROIC analysts identified a file called ultra uhq priv combs uploaded to Telegram. The name is combolist seller slang for ultra high quality private combos, and the file backs up that label with 3,458 records combining email addresses and plaintext passwords. Why This Is Dangerous: Sellers label files uhq, or ultra high quality, when the credentials have been checked and confirmed to work, meaning the accounts in this file are more likely to be live and unchanged. That makes this list more immediately useful to an attacker than an unverified dump. What Was Exposed: - Email addresses - Plaintext passwords - URLs for the associated login pages Why This Matters: A verified combolist like this one is often used right away for credential stuffing, account takeover, and resale to other criminals, since buyers pay a premium for lists that are known to work. If your email and password are in this file, the risk of an actual takeover attempt is higher than with a random unverified leak. How This Combolist Was Built: Sellers build private combos by testing stolen credentials from multiple sources against live login pages, keeping only the ones that succeed. The result is a smaller but more dangerous list than a raw, unchecked dump, which is exactly what the ultra uhq priv combs label is meant to signal to buyers. Check If You Are Affected: Run a free scan with HEROIC to check your email and passwords against this leak and more than 400 billion other breached records.
Breach Breakdown
3,458 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds