The noreplydiscord.com Leak Gave Hackers a Path Into 138 Accounts
On April 19, 2024, HEROIC's dark web monitoring team identified a combolist circulating on Telegram titled "noreplydiscord.com." The file contains 138 records pairing email addresses with plaintext passwords and the URLs each login was tied to.
Why the noreplydiscord.com Leak Is Dangerous
Because every password in this file sits in plaintext, an attacker does not need to crack or guess anything, they can read and use each login the moment they open the file. Combined with the associated URL, they know exactly where to try it first.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each login
Why This Matters for Your Accounts
With working email and password pairs in hand, an attacker can attempt to log in directly, and if any of the 138 people affected reused that password elsewhere, they can push further using credential stuffing to break into email, banking, or social media accounts tied to the same login.
How This Combolist Was Built
A combolist pairs usernames or emails with passwords, one per line, typically assembled from older breaches, phishing kits, and malware-infected devices. Once compiled and filtered down to working entries, files like this one are uploaded to Telegram channels where anyone can download and test them.
Check If You Are Affected
HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including this leak. Run a scan to see if your information showed up here and get clear steps to lock down your accounts.
Breach Breakdown
138 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds