Researchers Flag the Vuln_FTP Leak: 7,875 Logins Exposed Online
HEROIC researchers monitoring Telegram channels identified a file named Vuln_FTP in June 2026, containing 7,875 records of email addresses paired with plaintext passwords and the URLs those credentials were used on. Why This Combolist Is Dangerous: Analysts note the file's name references FTP, a protocol used to transfer files on servers, which suggests at least some of these credentials may belong to website or server logins rather than everyday consumer accounts. Because the passwords are unencrypted, they can be used immediately without any additional effort by an attacker. What Was Exposed: - Email addresses - Plaintext passwords - URLs associated with each login Why This Matters: Server and FTP-related credentials are especially valuable to attackers because gaining access to a website's backend can lead to defacement, malware injection, or theft of every visitor's data. For the individuals in this file, reused passwords also put personal email, banking, and shopping accounts at risk through credential stuffing. How a Combolist Like Vuln_FTP Comes Together: Researchers who track these files say they are typically assembled from scans of misconfigured or vulnerable servers, older data breaches, and phishing campaigns, then bundled together and shared in Telegram groups dedicated to trading stolen access. The generic naming pattern is common across these compilations and does not point to a single named company being breached. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records. Run a scan to see whether your credentials appear in Vuln_FTP or any other breach HEROIC has tracked.
Breach Breakdown
7,875 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds