Italian Alice.it Users Targeted in 20,376-Record KurdishPy Leak
In July 2026, HEROIC analysts identified a combolist labeled "21K_alice.it_KurdishPy" uploaded to a Telegram channel. Dated July 28, 2026, the file contains 20,376 records, each pairing an email address on the Italian alice.it domain with a plaintext password and an associated URL. The name attached to the file points to a threat actor or group operating under the handle "KurdishPy." Italian alice.it Users Are the Target of This Leak Unlike combolists pulled from many different email providers, this one focuses entirely on a single service, alice.it, an email provider used widely across Italy. Targeting one provider at this scale lets an attacker build a focused follow-up campaign, sending phishing emails that look like they come from alice.it itself, or testing the same credentials against other Italian services the same users are likely to use. What Was Exposed in the 21K alice.it Combolist alice.it email addresses Plaintext passwords Associated URLs Why This Matters With more than 20,000 working email and password pairs, attackers have plenty of material for credential stuffing, running each combination against banking sites, other email providers, and social media accounts. If you reused your alice.it password anywhere else, the risk extends well beyond your inbox to account takeover, identity theft, and financial fraud. Check If You Are Affected If you use an alice.it email address, or reuse the same password across multiple accounts, check now to see if you're one of the 20,376 people in this leak. HEROIC's free breach scanner searches more than 400 billion exposed records, so you can find out quickly and change any passwords that may have been compromised.
Breach Breakdown
20,376 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds