Inverted Risk: Just 49 Logins, But the Vuln_HestiaCP Leak Still Counts
In June 2026, HEROIC analysts found a small file called Vuln_HestiaCP on Telegram, containing 49 records of email addresses and plaintext passwords tied to HestiaCP, an open source hosting control panel. Why This Is Dangerous: Even though this list is small, just 49 accounts, HestiaCP credentials grant server-level access. A single working login can hand an attacker control of a server's websites, files, and email accounts, meaning the danger per account here is much higher than in a typical consumer credential leak. What Was Exposed: - Email addresses tied to hosting accounts - Plaintext passwords - URLs of the affected control panel logins Why This Matters: Small leaks are still real leaks. If you or your organization run HestiaCP and your credentials appear in a file like this, an attacker could gain full administrative control over your server, including every site and account hosted on it. How This Combolist Works: Attackers scan for exposed HestiaCP panels and test known or leaked password combinations against them. Successful logins are collected into a file like Vuln_HestiaCP and shared or sold, labeled specifically so a buyer knows what type of system access it provides. Check If You Are Affected: Run a free scan with HEROIC to check your email and passwords against this leak and the more than 400 billion records in HEROIC's breach database.
Breach Breakdown
49 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds