One Dark Web File. 68 Records. The Vuln_WHMs List Explained
In June 2026, HEROIC analysts found a file labeled Vuln_WHMs uploaded by a Telegram user. The file contains 68 records of email addresses and plaintext passwords tied to WHM, the Web Host Manager panel used by hosting providers and resellers to administer servers. Why This Is Dangerous: WHM accounts are not ordinary logins. A compromised WHM credential can give an attacker administrative control over an entire hosting server, meaning every website hosted on that server, along with its files, databases, and email accounts, becomes exposed. Even though this file only lists 68 accounts, the potential blast radius per account is far larger than a typical consumer login. What Was Exposed: - Email addresses tied to hosting accounts - Plaintext passwords - URLs of the affected WHM login panels Why This Matters: If any of these 68 credentials are still active, an attacker could take over hosted websites, redirect traffic, plant malware, or access customer data stored on those servers. This is the kind of access that turns one small leak into a much larger incident for everyone whose site sits on the affected server. How This Combolist Works: Attackers often scan the internet for hosting control panels with weak or reused passwords, then compile any working logins they find into a list like Vuln_WHMs, labeled to advertise exactly what kind of access it grants to a buyer. Check If You Are Affected: If you manage a hosting server or reseller account, check your email and passwords against HEROIC's free breach scanner, which searches over 400 billion exposed records.
Breach Breakdown
68 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds