How a Telegram Upload Exposed 661 Rai.it Email and Password Pairs
HEROIC analysts found a combolist uploaded to Telegram on June 10, 2026, titled rai.it - 661 emails, containing 661 records of email addresses tied to the rai.it domain, associated with Italy's public broadcaster, along with plaintext passwords and the URLs each login was meant for. Why This Is Dangerous: Because the passwords are stored in plaintext, an attacker can use the credentials immediately without needing to crack anything. Anyone in this file who reused their password elsewhere is at risk of having other accounts compromised too. What Was Exposed: Email addresses on the rai.it domain, plaintext passwords, and the login URLs tied to each account. Why This Matters: Work email accounts like these are often connected to internal systems and used to reset passwords on personal accounts. A compromised login here can lead to phishing attempts against coworkers, unauthorized access to internal tools, or account takeover on any other site where the password was reused. How This Combolist Was Built: Domain-specific lists like this one are typically created by filtering larger stealer malware or breach datasets for addresses matching rai.it, then packaged separately and shared on Telegram. This does not confirm that rai.it itself was directly breached, only that these addresses appeared in data already circulating among attackers. Check If You Are Affected: HEROIC's free breach scanner checks any email address against more than 400 billion leaked records. Run a free scan to see if your account, or one tied to your organization, has been exposed.
Breach Breakdown
661 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds