Moodle_VULNRCE Leak: Just 3 Accounts, Real Plaintext Passwords Exposed
HEROIC analysts identified a combolist file named Moodle_VULNRCE circulating in a Telegram channel on 17 February 2026. The file is small, containing just 3 records, but each one pairs a working email address with a plaintext password and a related URL. Why a Small File Still Puts People at Risk: A combolist this size might look insignificant next to breaches involving millions of accounts, but the risk to the 3 people in it is the same. Their email address, password, and the site the credentials belong to are sitting in plaintext, ready for anyone who downloads the file to try logging in immediately. No cracking or guessing is required. What Was Exposed: - Email addresses - Plaintext passwords - URLs linked to each account Why This Matters: Most people reuse the same password across several accounts. If any of the 3 exposed credentials match a password used elsewhere, an attacker can attempt credential stuffing against email, banking, or shopping accounts and take them over without ever contacting the victim. How a Combolist Like This Works: A combolist is simply a text file of username, email, and password combinations gathered from older leaks, stealer logs, or other combolists and repackaged for sharing. Files like Moodle_VULNRCE cost attackers nothing to obtain and require no technical skill to use, which is part of why they circulate so freely on Telegram. Check If You Are Affected: You can check whether your email address appears in this leak or any other breach in HEROIC's database of more than 400 billion exposed records using HEROIC's free breach scanner.
Breach Breakdown
3 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds