The “Security Alert” Combolist Just Surfaced: 140 Records Exposed
HEROIC analysts spotted a combolist titled "Security Alert" uploaded to Telegram on July 27, 2026, just days before this report. The file is small, 140 records total, pairing email addresses with plaintext passwords and the login URLs those credentials unlock. Why This Is Dangerous: Because this file surfaced so recently, the credentials inside are more likely to still be active than data from an older leak. An attacker doesn't need much time to start testing these logins before account owners have a chance to change them. What Was Exposed: - Email addresses - Plaintext passwords - URLs for the matching login pages Why This Matters: Ironically named "Security Alert," this file is itself the kind of thing a real security alert would warn you about. If your email and password appear here, an attacker can use them for credential stuffing across other accounts within days of upload, leading to account takeover before you'd notice anything unusual. How a Combolist Like This Works: Small, freshly uploaded combolists like this one are often the direct output of a phishing campaign or a short malware run, collected and shared quickly while the data is still fresh and more likely to work. Check If You Are Affected: Because this leak is recent, it's worth checking now rather than later. Search your email against this file and HEROIC's database of more than 400 billion exposed records with HEROIC's free breach scanner, and change your password immediately if you find a match.
Breach Breakdown
140 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds