Is Your Login in the ‘Gift From WhyAlwaysMex’ Leak of 54?
On 5 December 2024, a combolist titled "GIFT FROM WHYALWAYSMEX" was uploaded to Telegram. HEROIC's monitoring confirmed the file contains 54 records, each pairing an email address with a plaintext password and an associated URL.
Why This Is Dangerous
The word "Gift" in the title suggests this combolist was shared freely rather than sold, likely to build reputation for the uploader within their community. A free giveaway still means real credentials in the wrong hands, and each of these 54 records includes a plaintext password ready for immediate use.
What Was Exposed
The "GIFT FROM WHYALWAYSMEX" combolist contains:
- Email addresses
- Plaintext passwords
- Associated URLs
Why This Matters
Even a list of just 54 accounts causes real harm to the specific people affected. If you're one of them and you've reused that password on another site, an attacker could use it to attempt account takeover, and from there, potentially commit identity theft or financial fraud.
How This Combolist Was Built
Small combolists like this one are often carved out from larger breach collections and given a personal or attention-grabbing name, in this case referencing the uploader's own username, before being posted for free to attract followers or build credibility on Telegram. The underlying credentials are typically recycled from older breaches, phishing pages, or malware logs.
Check If You Are Affected
Because this list is small, it's easy to check whether you're one of the 54 people affected. HEROIC's free breach scanner searches more than 400 billion leaked records, including this combolist, so you'll know in seconds.
Breach Breakdown
54 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds