Researchers Track a Second Vuln_FTP Leak: 3,811 Logins Exposed
HEROIC researchers tracking Telegram breach channels identified another file named Vuln_FTP, dated 27 June 2026, separate from an earlier upload using the same name. This version contains 3,811 records pairing email addresses with plaintext passwords and the URLs each login was used on. Why This Combolist Is Dangerous: As with similarly named files, the reference to FTP suggests some of these credentials may be tied to server or website logins rather than personal email accounts alone. Because the passwords are stored as plaintext, they can be used the moment someone downloads the file, with no decryption needed. What Was Exposed: - Email addresses - Plaintext passwords - URLs associated with each credential Why This Matters: Repeated uploads using the same generic name suggest ongoing scanning or credential harvesting activity rather than a single one-time event. If your login shows up in a file like this, it means your credentials have been circulating in criminal channels, putting any account using the same password at risk of takeover. How Combolists Like Vuln_FTP Keep Reappearing: When a naming pattern like this shows up more than once, it usually means the uploader is running an ongoing operation, whether scanning for exposed servers, harvesting new phishing victims, or simply splitting a larger data set into smaller files released over time. Check If You Are Affected: Run your email through HEROIC's free breach scanner, checking against more than 400 billion leaked records, to see if you appear in this Vuln_FTP file or any other exposure HEROIC tracks.
Breach Breakdown
3,811 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds