jd.com_decrypt Combolist Leak Has More Records Than Missouri
A Decrypted Password File Tied to jd.com Surfaced on Telegram
On 20 August 2023, HEROIC analysts identified a combolist uploaded to Telegram under the file name "jd.com_decrypt_03.06.2021.txt." The name suggests the file is a decrypted password set referencing jd.com and dated internally to March 2021, though as with most Telegram-sourced combolists, the file itself was simply uploaded by an individual user rather than distributed directly from a company breach notice. In total, the list contained 6,321,209 records, each combining an email address, a plaintext password, and the URL of the login page the credentials were meant to access.
Why This Is Dangerous
At more than 6.3 million entries, this is one of the larger combolists HEROIC has tracked recently, and every password in it is stored in plain, unencrypted text. That means anyone who obtains the file can read a person's password exactly as it was typed, with no cracking or guessing required. Combined with the matching email address and site URL, an attacker has everything needed to attempt a direct login.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the associated login pages
Why This Matters
Files this size are typically fed into automated credential stuffing tools that test each email and password pair against major email providers, banks, and retail accounts within minutes. Anyone who reused this password on another site is exposed to account takeover, even if the original source of the password was never breached themselves. From there, attackers can pivot to identity theft, unauthorized purchases, and further financial fraud using whatever personal details those accounts hold.
How Decrypted Combolists Like This One Are Made
A "decrypt" combolist usually starts as an older password dump that was originally stored in an encrypted or hashed format. Someone, often working with leaked encryption keys, cracking tools, or a previous unauthorized decryption, converts those hashes back into plaintext passwords and repackages the result as a clean, ready-to-use list. These files then circulate through Telegram channels and dark web forums, where they are traded, sold, or given away to anyone who wants a large batch of working credentials.
Check If You Are Affected
With more than 6.3 million accounts involved, the odds that your email address is in this list are real. HEROIC's free breach scanner checks your email against a database of over 400 billion leaked records, including combolists like this one, so you can find out in seconds and change any reused passwords before they are put to use.
Breach Breakdown
6,321,209 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds