Just Surfaced: 20M Private ULPJune-2026 uploaded by a Telegram User
What HEROIC Analysts Found
HEROIC's dark web monitoring team identified a large combolist titled "20M Private ULPJune-2026 uploaded by a Telegram User," dated to 27 June 2026. The file contains 15,618,131 records pairing email addresses with plaintext passwords, along with the URLs of the sites those credentials belong to. It surfaced only weeks ago on a Telegram channel used to trade combolists, with affected individuals located in the United States.
Why This 15.6 Million Record Leak Is Dangerous
The sheer size of this file is what makes it so valuable to attackers. Every password inside is stored in plaintext, so there is no need to crack or decrypt anything before using it. A file this large gives attackers a ready-made list to run against login pages at scale, testing millions of email and password combinations in a fraction of the time it would take to target people individually.
Because each record also includes the URL the credentials were used on, attackers can sort and target specific types of accounts quickly, going straight for banking portals, email providers, or other high-value logins tied to a reused password.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs associated with each set of login credentials
Why This Matters
A combolist of this size is built for credential stuffing at scale, where automated tools test millions of stolen email and password pairs against other websites in a short amount of time. If your password was reused anywhere else, this leak alone could be enough to trigger account takeover well beyond the original login it was tied to.
From there, the fallout can spread quickly into identity theft and financial fraud, particularly if a compromised email account is used to reset passwords on banking or shopping accounts.
How Combolists Work
A combolist is a large compiled file of email-and-password pairs, typically gathered from multiple older breaches or malware infections and repackaged for free distribution or resale on platforms like Telegram. What separates a combolist from a single company's breach dump is scale: files like this one, with more than 15 million records, blend credentials from many different sources into one resource attackers can run against thousands of websites at once.
Check If You Are Affected
With more than 15 million records now circulating, the only way to know if you are one of them is to check. HEROIC's free breach scanner searches more than 400 billion leaked records, including combolists like this one, to tell you whether your email and password have been exposed. If they have, change that password immediately and stop reusing it elsewhere.
Breach Breakdown
15,618,131 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds