Search Your Email: 2.1KK Mix Base Telegram Leak Exposed 1M+ Records
HEROIC analysts identified a combolist circulating on Telegram in March 2023 known as the 2.1KK Mix Base. The file, uploaded by a Telegram user, contained 1,092,701 records pairing email addresses with plaintext passwords, along with associated URLs. Unlike a breach of a single company, this combolist appears to be a compiled collection of credentials pulled together from multiple sources and repackaged for resale or free distribution on Telegram.
Why a Plaintext Password Combolist Is Dangerous
Because the passwords in this file are stored in plaintext rather than hashed or encrypted, anyone who downloads the 2.1KK Mix Base file can use the credentials immediately with no cracking required. An attacker can plug an email and password pair straight into a login page and, if that person reused the password anywhere else, get in on the first try. The included URLs make this worse, since they often point attackers directly to the site each credential pair belongs to, cutting out the guesswork of finding where to use stolen logins.
What Was Exposed in the 2.1KK Mix Base File
- Email addresses
- Plaintext passwords
- Associated URLs linking credentials to specific login pages
Why This Matters for Anyone in the File
Combolists like this one are a core tool in credential stuffing attacks, where automated scripts test stolen email and password pairs against banks, email providers, social media, and shopping sites at massive scale. If your credentials are in the 2.1KK Mix Base, and you have reused that password anywhere, you are at risk of account takeover, financial fraud, and identity theft. Even a small file like this one can do real damage because attackers do not care about the size of the source, only whether the login works.
How a Combolist Like This Gets Built and Sold
A combolist is a compiled file of email and password combinations, often assembled from older breaches, phishing campaigns, or malware infections and merged into one document. Sellers and Telegram users package these lists for others to use in credential stuffing, sometimes labeling them by size or content, as with this 2.1KK ("2.1 million") mix base. Because the data is combined from multiple sources, the passwords are frequently already known to attackers, which is exactly why they are shared this way instead of kept private.
Check If You Are Affected
If you want to know whether your email address appears in the 2.1KK Mix Base or any of the other breaches and combolists HEROIC tracks, use HEROIC's free breach scanner. It checks your information against a database of more than 400 billion leaked records so you can find out quickly and take action, like changing reused passwords, before someone else uses them first.
Breach Breakdown
1,092,701 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds