What Attackers Do With 561,866 Private_Usa_Combo Logins
HEROIC analysts found a combolist named Private_Usa_Combo dated January 15, 2026, holding 561,866 exposed records. The file pairs email addresses with plaintext passwords and the URLs those logins were gathered against, built specifically to be tested against other websites. Scanning your email is the only way to know if you're in it.
561,866 Logins, Built for Reuse Testing
A combolist isn't the product of one company getting hacked, it's a pile of email and password pairs collected from many places and assembled into one list. The whole point of a file like Private_Usa_Combo is to feed those pairs into automated tools that try each one across dozens of other sites at once.
Because the passwords are plaintext, that testing can start the moment the file changes hands, with no cracking step in between.
What Sits Inside Private_Usa_Combo
- Email Addresses: works as the username half of each login and a target for phishing emails.
- Plaintext Password: readable immediately, so it's ready to test against accounts with no extra effort.
- URLs: shows which site or service each credential pair was originally tied to.
Why 561,866 Records Is a Scale Problem
At this size, an attacker isn't targeting anyone specifically, they're running every pair through automated login attempts and keeping whatever sticks. Any account that shares a password with this list becomes collateral damage, even if that account had nothing to do with wherever the password originally leaked from.
The result is account takeover across unrelated services, plus a jump in targeted phishing once a working email and password pair confirms someone's real accounts.
How a Combolist Like This Gets Built
Combolists are stitched together from older leaked credentials, pulled from various sources and combined into one large file of email and password pairs. There's no single hack behind it, just collection and consolidation aimed at making reuse testing efficient. The bigger the list, the more valuable it is to whoever is running those automated login attempts, which is how a file reaches 561,866 records.
Is Your Login Inside the Private_Usa_Combo List?
Scan your email to check whether it appears in this list. If it does, change that password everywhere you've used it, not just on one account, since the whole risk here comes from password reuse across sites.
This applies equally to a personal email and a work one, review both for reused passwords.
Breach Breakdown
561,866 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds