The sigen.cofen.gov.br File Contains Exactly 10 Login Records
Exactly 10 records, no more, no less. That's the full contents of a file tied to sigen.cofen.gov.br, uploaded to Telegram in August 2026 and reviewed by HEROIC analysts. Each of the 10 pairs an email address with a plaintext password and the login URL it was captured on. Scan your email to see if you're one of the exact 10.
Why a Precise, Small Count Still Deserves Attention
There's nothing padded or exaggerated about a file this size. Every one of the 10 records is a confirmed, working login, which makes the file smaller but no less usable to whoever holds it. A precise count like this often means the entries were checked individually rather than scraped in bulk and left unverified.
What Was Exposed
- Email addresses: identify the account tied to each of the 10 records.
- Plaintext passwords: readable and usable immediately, with nothing to crack.
- URLs: confirm each credential was captured on sigen.cofen.gov.br.
What Happens With a Confirmed Login
An attacker can log in directly, or check whether the same password was reused on other sites, extending the reach of a small file well beyond its original 10 records into whatever other accounts share that same password.
How a File This Precise Gets Made
Small, exact batches like this are usually filtered from a larger stolen credential collection and verified one by one against a single login page, which is why the count comes out so precise rather than rounded.
See if You're One of the 10
Scan your email to check. If you're listed, change that password immediately and anywhere else you reused it, from a device you trust. This matters equally for personal and work accounts.
Breach Breakdown
10 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds