Inside the RDHQ_MailAccess Combolist: How 4,236 Logins Leaked Online
HEROIC analysts identified a combolist titled "RDHQ_MailAccess_Combos_2," uploaded to a Telegram channel on June 5, 2026. The file contains 4,236 records of email addresses, plaintext passwords, and the login URLs tied to each account.
Why This Is Dangerous
This is the second version of this particular combolist to surface, suggesting the underlying data has been reworked or expanded before being reposted. Every record pairs a working email with a plaintext password and login URL, letting an attacker sign in directly without cracking anything.
What Was Exposed
- Email addresses
- Plaintext passwords
- Account login URLs
Why This Matters
Repackaged combolists like this one often circulate quietly for a long time before appearing publicly, giving attackers a head start on testing the credentials before most affected users are even aware. Anyone who reused a password from this list on another site remains at risk even after changing the original one.
How Combolists Work
A combolist pairs usernames or emails with passwords, typically compiled from earlier leaks or malware infections and shared on platforms like Telegram. Files labeled with version numbers, like "_2" here, usually mean the same source data has been cleaned up, merged, or resold more than once.
Check If You Are Affected
HEROIC's database holds more than 400 billion records from combolists, stealer logs, and confirmed breaches. Run a free scan to check if your email appears in the RDHQ_MailAccess_Combos_2 dump or any other exposure, and get clear steps to secure your accounts.
Breach Breakdown
4,236 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds