KurdishPy Combolist: 10,208 Emails and Passwords Leaked Just Days Ago
HEROIC analysts identified a combolist file titled "10K_Australia_KurdishPy" that surfaced on a Telegram channel on July 28, 2026. The file contains 10,208 records pairing email addresses with plaintext passwords, along with the URLs those credentials were tied to. Why This Is Dangerous: The passwords in this file are stored in plaintext, meaning anyone who downloads it can use the credentials immediately, no cracking or guessing required. If any of the 10,208 people in this list reused a password on another account, an attacker can log straight in. What Was Exposed: - Email addresses - Plaintext passwords - URLs linked to the accounts Why This Matters: Combolists like this one are fuel for credential stuffing attacks, where automated tools test each email and password pair against banking sites, email providers, and social media platforms. A single reused password can lead to account takeover, identity theft, or direct financial fraud. How a Combolist Like This Works: A combolist is a compiled file of username or email and password pairs, often pulled together from older breaches, phishing pages, or infected devices, then repackaged and shared on Telegram or hacking forums. Because the entries can come from multiple sources, it is often impossible to know exactly which site each password was originally used on, which is part of why these files spread so widely and quickly. Check If You Are Affected: HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including combolists like this one. It takes a few seconds to see if your information showed up in this or any other exposure.
Breach Breakdown
10,208 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds