The MAIL ACCESS 10K MIX VALID 100 Dump Exposed 10,301 Inboxes
On June 3, 2026, HEROIC's dark web monitoring team identified a combolist circulating on Telegram titled "MAIL ACCESS 10K MIX VALID 100." The file contains 10,301 records pairing email addresses with plaintext passwords and the URLs each login was used on.
Why the MAIL ACCESS 10K MIX VALID 100 Leak Is Dangerous
The "Valid" label means these email logins have already been checked and confirmed to work, and the "mix" in the name signals credentials pulled from a range of email providers rather than just one. Since the passwords sit in plaintext, an attacker can read and use each one immediately.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each login
Why This Matters for Your Accounts
Direct access to an inbox is one of the most valuable things an attacker can get. Email accounts are used to reset passwords and receive security codes for almost everything else, so if your address is among the 10,301 in this file, an attacker with access to your inbox can potentially take over your other accounts too.
How This Combolist Was Built
A combolist pairs email addresses with passwords, one entry per line, compiled from older breaches, phishing campaigns, and malware-infected devices, then validated by testing each login before release. A "mix" file like this one pulls confirmed working credentials from multiple email providers into a single package sold or shared on Telegram.
Check If You Are Affected
HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this leak. Run a scan to see if your inbox was exposed, and get clear steps to secure it.
Breach Breakdown
10,301 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds