One Listing. Just 3 Records. The Rackspace Combolist Leaked Logins.
HEROIC analysts identified a very small combolist labeled "Rackspace" uploaded to Telegram in July 2026. The listing contains only 3 records, each pairing an email address with a plaintext password and a URL pointing to the login page the credentials were used on. The listing is associated with the United States and has been marked as a verified breach entry, though its small size suggests a narrowly targeted file rather than a large-scale corporate incident. Why the Rackspace-Labeled Combolist Is Still Worth Attention: A file with just 3 records will never generate headlines, but the risk to the specific individuals involved is real. The passwords are stored in plaintext, meaning whoever holds this file can use the credentials immediately without cracking or decrypting anything. Because the listing references Rackspace, an attacker could specifically be targeting hosting or cloud account access rather than casting a wide net. What Was Exposed in This Combolist: email addresses used as usernames, plaintext passwords stored without encryption, and URLs identifying the exact login page tied to each account. Why This Matters Even for Just 3 Records: If you use Rackspace services and your password shows up in a leak like this, an attacker could attempt to log directly into your hosting or cloud account. Worse, if that same password is reused on other platforms, the risk extends to credential stuffing against your email, financial, or business accounts, opening the door to account takeover and financial fraud. How a Combolist Like This One Works: A combolist pairs usernames or emails with matching passwords, typically compiled from phishing pages, malware infections, or older breaches, then shared or sold on platforms like Telegram. Small, targeted combolists like this one are often built around a specific service or small group of accounts rather than a mass breach, which is why the record count here is so low. The credentials are packaged in a way that lets anyone plug them straight into a login attempt with no further work. Check If You Are Affected: Even a leak this small deserves a check, especially if you use the service referenced in the listing. HEROIC's free breach scanner searches a database of more than 400 billion exposed records, including small combolists like this one, so you can find out in seconds whether your email address appears in this leak or any other breach on file.
Breach Breakdown
3 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds