The Somalia Corp Mails Test Sample Leak Put 1,042 Logins Online
HEROIC analysts identified a Telegram combolist labeled "SOMALIA CORP-OTHERS-PRO MAILS TEST SAMPLE" that surfaced on February 22, 2026. Despite the "test sample" label, the file contained 1,042 real records pairing email addresses with plaintext passwords and account URLs. Why This Is Dangerous: The word "sample" in the file name does not mean the data is fake. All 1,042 records include plaintext passwords, meaning anyone who obtains the file can log into the listed accounts right away without any additional effort. What Was Exposed: - Email addresses - Plaintext passwords - Account login URLs Why This Matters: Files labeled as corporate "mail" collections are often used to target businesses, since a single compromised work email can lead to further access across an organization. If any of these 1,042 accounts reused passwords elsewhere, attackers can use credential stuffing to break into personal banking, shopping, or social accounts too. How This Telegram Combolist Was Built: Combolists like this one are typically compiled from older breaches, malware-infected devices, or phishing campaigns, then packaged and shared on Telegram, sometimes labeled as "samples" or "tests" to downplay their contents before a larger file is sold or distributed. The credentials remain fully usable regardless of the label. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including combolists like this one. Run a scan to see if your information appears in this or any other leak.
Breach Breakdown
1,042 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds