Dark Web Intel: 1,250 Records in the “Norway_samples” Leak
HEROIC analysts tracked a combolist titled "Norway_samples" uploaded to Telegram on May 21, 2026, containing 1,250 records of email addresses, plaintext passwords, and login URLs. The name suggests a Norwegian connection, but the country data on file for this leak is a generic, unverified placeholder, so HEROIC cannot confirm the nationality of the people affected. Why This Is Dangerous: Wherever these accounts are actually based, every record includes a plaintext password tied to a specific email and login page, enough for an attacker to attempt a direct sign-in without any additional work. What Was Exposed: - Email addresses - Plaintext passwords - URLs for the matching login pages Why This Matters: The word "samples" in the filename suggests this may be a preview of a larger dataset the uploader is advertising for sale elsewhere. Even as a sample, the 1,250 records here carry the same credential stuffing and account takeover risk as any full-sized leak. How This Kind of Leak Circulates: Sellers on Telegram and dark web forums often release small "sample" files to prove a larger dataset is real before selling the full version privately. These samples are usually genuine, functioning credentials meant to build buyer confidence. Check If You Are Affected: Treat a sample leak with the same seriousness as a full one. Check your email against this file and HEROIC's database of more than 400 billion exposed records using HEROIC's free breach scanner.
Breach Breakdown
1,250 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds