Researchers Link a LATVIA Mail Sample Dump to 1,072 Stolen Logins
In February 2026, HEROIC analysts identified a combolist labeled "LATVIA CORP-OTHERS-PRO MAILS TEST SAMPLE" shared on a Telegram channel used to distribute stolen credentials. The file contained 1,072 records pairing email addresses with plaintext passwords and the URLs of the accounts they open.
Why This Is Dangerous
Despite being labeled a "test sample," the credentials inside are real and readable in plaintext. Anyone who obtains the file can immediately try each email and password combination against other online services, hoping account owners reused the same password.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tying each credential pair to a specific account
Why This Matters
Files labeled as "samples" are often smaller previews of a larger dataset a seller is trying to advertise. Even at 1,072 records, anyone whose email appears here faces the same account takeover risk as in a much larger leak if they have reused their password.
How Combolists Work
Combolists are compiled lists of email-and-password pairs, often gathered from previous breaches or malware-infected computers and packaged for sale or free distribution. Sellers sometimes release a small "test sample" like this one to prove the data is real before selling the full file, and buyers run these lists through automated tools that test each credential pair against many websites at once.
Check If You Are Affected
Run a free scan against HEROIC's database of more than 400 billion leaked records to see whether your email address appears in this sample or in the wider dataset it may be drawn from.
Breach Breakdown
1,072 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds