Researchers Confirm 107,025 Logins in the ‘108K Mixed’ Leak
HEROIC researchers reviewed a Telegram upload titled 108K Mixed Domains in July 2026 and confirmed 107,025 actual records, slightly below the rounded number in the file's name. Each record pairs an email address with a plaintext password and the URL the login belongs to. Why This Combolist Is Dangerous: As the name suggests, this file mixes credentials from many different websites rather than one single service. That variety makes it especially useful to attackers running credential stuffing campaigns, since a single file can be pointed at hundreds of different targets at once. What Was Exposed: - Email addresses - Plaintext passwords - URLs spanning a wide range of different domains Why This Matters: Because the domains are mixed, researchers note this file was likely built for broad, automated attacks rather than targeting one company's customers. If your credentials appear here, an attacker could try them against many unrelated services in a short period, increasing the odds that a reused password leads to a real account compromise somewhere. How a 'Mixed Domains' Combolist Like This Is Assembled: Researchers say these files are typically built by aggregating credentials harvested from many separate phishing pages, malware infections, and older breaches, then combining them into one file organized by nothing more than the fact that they were all collected around the same time. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records. Run a scan to see whether your login appears in 108K Mixed Domains or any other exposure on file.
Breach Breakdown
107,025 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds