One UHQ Combolist Password Could Unlock All Your Accounts
In January 2023, HEROIC detected a stealer log collection titled "20K UHQ Combolist Mixed" being distributed on Telegram. This high-quality credential dump contains 17,840 records with plaintext passwords, giving threat actors a ready-made toolkit for breaking into user accounts across the internet.
Plaintext Passwords Leave Zero Room for Defense
Every password in this combolist is stored in plaintext—completely unencrypted and readable by anyone with access to the file. There is no hash to crack, no algorithm to reverse. Attackers can simply read a password and type it into a login form. For the 17,840 users whose credentials appear here, the window to act is already closing fast.
What Was Exposed
- Email Addresses — primary account identifiers across multiple platforms
- Plaintext Passwords — exposed in clear text with no protection whatsoever
- URLs — direct links to the websites where credentials were harvested
The Chain Reaction of Reused Credentials
When attackers obtain a working email-password pair, they do not stop at one account. Credential stuffing—the automated process of testing stolen credentials across many services—turns a single breach into a cascade of compromises. If you use the same password for your email, bank, and shopping accounts, one entry in this combolist could hand over access to all of them. The 17,840 records in this dump represent thousands of potential chain reactions waiting to happen.
What Are Stealer Logs and UHQ Combos?
"UHQ" stands for Ultra High Quality, a label used by cybercriminals to indicate that the credentials have been verified as working or recently active. These credentials originate from stealer logs—data harvested by infostealer malware installed on victims' devices through phishing, pirated software, or exploit kits. The malware silently extracts saved passwords from browsers, email clients, and applications, then sends them to command-and-control servers where they are packaged into combo lists for sale or free distribution.
Check If Your Credentials Were Exposed
With 17,840 records in circulation, the odds of being affected are real. Use HEROIC's breach scanner to check your email address against more than 400 billion compromised records. If your credentials appear in the 20K UHQ Combolist Mixed dump or any other breach, you will know immediately—giving you the chance to change passwords and enable two-factor authentication before damage is done.
Breach Breakdown
17,840 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds