SFR.fr Users Targeted: KurdishPy Leaked 297 Emails and Passwords
HEROIC analysts found a small combolist labeled "300_sfr.fr_KurdishPy" circulating on Telegram on July 28, 2026. The file contains 297 records of email addresses and plaintext passwords tied to sfr.fr accounts, along with associated URLs. Why This Is Dangerous: The credentials in this file are not encrypted or hashed, they are stored as plain text. That means anyone who gets the file can use the email and password combinations right away, with no extra work needed to crack them. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to the sfr.fr accounts Why This Matters: Even a small leak like this one carries real risk for the people in it. If any of these 297 users reused their sfr.fr password on another site, such as email, banking, or social media, an attacker could use the same credentials to take over those accounts too. That is how a single leaked password often leads to identity theft or financial fraud far beyond the original account. How a Combolist Like This Works: A combolist is a text file pairing usernames or emails with passwords, usually pulled together from older breaches, phishing pages, or malware and then repackaged for sale or free distribution on Telegram. Smaller combolists like this one are often carved out from larger sources and focused on a specific domain or service, in this case accounts linked to sfr.fr. Check If You Are Affected: HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, so you can quickly find out if your information appeared in this combolist or any other exposure.
Breach Breakdown
297 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds