Mix 1 Dump: 2,176 Stolen Login Credentials Hit the Dark Web
What HEROIC Analysts Found
In July 2026, HEROIC analysts identified a combolist file labeled "Mix 1," uploaded to a Telegram channel. The file contained 2,176 records pairing email addresses with plaintext passwords, along with the URLs of the sites those logins belong to.
Why This Is Dangerous
Each line in this file pairs a working email and password with the exact website it belongs to, all stored as plain, readable text. There is no cracking involved: anyone who gets the file can copy a login and try it on the matching site right away.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs linking each login to the site it belongs to
Why This Matters
Even a relatively small file like this one carries real risk for the people in it. If any of these accounts reuse the same password on other sites, an attacker can use this leaked login to attempt credential stuffing against email, banking, or shopping accounts belonging to the same person.
How Combolists Work
A combolist is a compiled file of email or username and password pairs, usually pulled from earlier breaches, stealer logs, or leaked databases. A "mix" combolist blends credentials from more than one source into a single file, which is often shared or sold on Telegram after being run through checker tools that confirm which logins still work.
Check If You Are Affected
If you want to know whether your email address shows up in this leak or any other, HEROIC's free breach scanner checks it against a database of more than 400 billion leaked records. Search your email now to see if a password change is overdue.
Breach Breakdown
2,176 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds