Our Analysts Found the Mansory 6 Combolist With 1.4 Million Logins
HEROIC's analysts found a combolist called "mansory 6" circulating on a Telegram channel used to trade stolen credentials, dated 9 December 2025. The file is large: 1,445,909 records, each pairing an email address with a plaintext password and the URL of the account it opens.
Why This Is Dangerous
At nearly 1.5 million entries, this is one of the larger combolists HEROIC has tracked recently. Every password inside is stored as plain, readable text, meaning attackers can immediately load the entire file into automated tools and start testing logins at massive scale across banking, email, and shopping sites.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs identifying the account each credential pair belongs to
Why This Matters
A file this size gives attackers enough volume to run credential stuffing campaigns against major online services with real success rates, simply because some percentage of 1.4 million people will have reused their password elsewhere. Anyone in this file faces a heightened risk of account takeover, identity theft, or financial fraud if their password has not been changed.
How Combolists Work
Large combolists like "mansory 6" are usually built by merging many smaller breaches, phishing hauls, and stealer logs into a single master file. Attackers then run the entire list through credential stuffing software that automatically tests every pair against hundreds of websites in a short period of time, looking for any account where the password still works.
Check If You Are Affected
Search your email address against HEROIC's database of more than 400 billion leaked records, including the "mansory 6" combolist, with a free scan, and change any password you have reused elsewhere.
Breach Breakdown
1,445,909 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds