One File Named TXT_ALIENS. Nearly 30 Million Stolen Logins.
One file. Nearly 30 million stolen logins. In May 2026, HEROIC analysts identified a combolist named TXT_ALIENS - 1633 uploaded to a Telegram channel, containing 29,991,447 records that pair email addresses with plaintext passwords and the URLs each login was used on. Why This Combolist Is Dangerous: This is one of the largest single files HEROIC has tracked recently. Every credential is stored in plaintext, so there is no encryption to break before an attacker can start testing logins against websites at massive scale. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each of the nearly 30 million login pairs Why This Matters: At this scale, automated bots can run through the entire file in a matter of hours, checking every pair against thousands of banking, email, retail, and social media sites. If your password shows up here and you reuse it elsewhere, the odds of account takeover, identity theft, or financial fraud rise sharply. How a Combolist of This Size Gets Built: Files this large are almost never a single breach. They are typically stitched together from dozens or hundreds of smaller data sets, including older leaks, phishing harvests, and malware logs, then merged, deduplicated, and shared under a code name like TXT_ALIENS on Telegram channels dedicated to trading stolen credentials. Check If You Are Affected: With nearly 30 million records in play, checking your email is worth the minute it takes. HEROIC's free breach scanner searches more than 400 billion leaked records, including this one, to tell you if you need to change a password.
Breach Breakdown
29,991,447 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds