3,793,847 Records Exposed in “output 3” Telegram Combolist
On October 1st, 2024, a plain-looking file called "output 3" started making the rounds in a Telegram channel dedicated to trading stolen logins. Inside were 3,793,847 individual records, each one pairing an email address with a plaintext password. No company ever announced a hack. No news outlet covered it. It just appeared, the way most combolists do, and quietly began fueling attacks against accounts that have nothing to do with where the data originally came from.
Why This Is Dangerous
A combolist this size is dangerous precisely because it looks boring. There's no dramatic hacker group behind it, no ransom note, just a giant spreadsheet-style dump of email and password pairs pulled together from older, unrelated breaches. Criminals don't need to break into anything new to use it. They just need people to have reused a password somewhere, which, realisticly, a huge number of people still do. That single habit is what turns an old, forgotten leak into a fresh problem years later.
What Was Exposed
- 3,793,847 total records bundled into a single combolist file
- Full email addresses tied directly to each entry
- Passwords stored and shared in plaintext, with zero encryption
- Associated URLs indicating which sites or services the logins were meant for
Why This Matters
Even if you don't recall ever using a site connected to this specific file, your credentials could have been swept up in it from an earlier, unrelated incident and repackaged here. Combolists get recycled, renamed, and resold constantly, so a password you changed years ago might still be sitting in circulation today, waiting for someone to try it against your email, your bank, or your work login.
How Combolists Work
Combolists are assembled by collecting credentials from multiple prior breaches and merging them into one master list, often cleaned up and formatted so automated tools can use them efficiently. Attackers then run these lists through credential stuffing software, which imediately tests each email and password pair against hundreds of popular websites at once. Anywhere the password gets reused, the attacker walks straight into that account without needing to guess or crack anything.
Check If You Are Affected
The only way to know for sure if your information is sitting inside this or any other leaked dataset is to actually check. HEROIC's free scanner searches across more than 400 billion leaked records, including combolists like this one, and will tell you right away if your email shows up. It takes a minute, and it's a lot better than finding out the hard way after someone else has already logged in as you.
Breach Breakdown
3,793,847 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds