Breach Intelligence Report 03 Aug 2026

The Mikel Base UHQ Combolist: 2,158,687 US Records Exposed

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Combolist 2.7KK USA HEAVY MIKEL BASE UHQ uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 2,158,687
Source Type Combolist
Origin United States
Password Type plaintext

The "Mikel Base UHQ" Combolist: 2,158,687 Records, Not 2.7 Million

HEROIC analysts identified a combolist file labeled "2.7KK USA HEAVY MIKEL BASE UHQ," uploaded to a Telegram channel and dated December 10, 2022. Despite the "2.7KK" (meaning roughly 2.7 million) in its name, HEROIC's analysis confirms the file actually contains 2,158,687 records, each pairing an email address with a plaintext password and a matching URL. The "UHQ" label, short for "ultra high quality," is dark web shorthand sellers use to market combolists as containing fresher, more reliable credentials.


Why This Is Dangerous

With more than two million email and plaintext password pairs in a single file, an attacker has enormous scale to work with, and no cracking is required since the passwords are not hashed. The paired URLs point directly to each account's login page, and the "UHQ" branding signals the seller claims these credentials are more likely to still be active than a random older dump.


What Was Exposed

  • Email addresses
  • Plaintext passwords
  • URLs linked to the accounts

Why This Matters

A file of this size sits near the top of the underground credential market precisely because of its volume and marketed quality. Criminals load lists like this into automated tools to run credential-stuffing attacks against banking sites, email providers, and online retailers, testing whether people reused their password elsewhere. At over two million records, even a small success rate translates into a large number of account takeovers, financial fraud cases, and identity theft incidents.


How "UHQ" Combolists Are Marketed in the Underground Economy

A combolist is a plain-text file of "combo" entries, an email or username paired with a password. Within the dark web credential trade, sellers grade and label their lists much like any other product line, tagging some as "fresh," others as "UHQ" or "heavy," to signal size and quality to buyers. These files are usually assembled from older breach data, phishing hauls, or malware infections, then packaged and marketed on Telegram channels and dark web forums under names designed to sound more valuable than the underlying data actually is.


Check If You Are Affected

Given the scale of this combolist, checking your exposure is worth the couple of minutes it takes. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including large combolists like this 2,158,687-record file, so you can find out if your email and password combination is circulating and update your credentials before someone else does.

Breach Breakdown

Domain 2.7KK USA HEAVY MIKEL BASE UHQ uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 03 Aug 2026
Check in 5 seconds

2,158,687 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,044 scanned today
Breach Rank #N/A by affected users
Impact Score
40
sensitivity + scale + recency
Est. Financial Impact $15.6M fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance