Someone Has Your Password: 356,899 Credentials Leaked
HEROIC detected a large-scale combolist labeled "300K Combo" shared on Telegram in March 2025 that actually contains 356,899 compromised records. Each entry pairs an email address with a plaintext password and the associated URL, creating a massive database of login credentials spanning a wide range of online services. Combolists of this size are routinely weaponized for automated account takeover campaigns targeting millions of users.
Nearly 357,000 Passwords Exposed in Plaintext
Every credential in this combolist appears in plaintext with no encryption whatsoever. At this scale, the raw volume alone guarantees that thousands of these credentials will still be active and usable. Attackers can begin testing these email-password combinations against live services the moment they download the file, with no cracking or decryption step needed. The sheer number of exposed credentials makes this dump a high-priority threat.
What Was Exposed
- Email Addresses — spanning multiple providers across hundreds of thousands of accounts
- Plaintext Passwords — immediately exploitable, no decryption required
- URLs — mapping out which services and platforms each credential belongs to
Why Massive Combolists Demand Urgent Action
Combolists of this magnitude fuel industrial-scale credential stuffing. Automated botnets can test all 356,899 combinations against banking, email, shopping, streaming, and cloud services within a single day. For every person in this dump who has reused their password, the risk multiplies across every linked account. The combination of volume and variety makes combolists like this one the backbone of automated cybercrime operations.
The Infostealer Supply Chain
This combolist was compiled from credentials harvested by infostealer malware across thousands of individual infections. Each victim's device contributed a set of stolen logins, which were then aggregated, deduplicated, and packaged into this 300K+ record collection. The malware responsible typically spreads through pirated software, malicious advertisements, and phishing emails. These compiled combolists are then distributed on Telegram, sold on dark web forums, or used directly in attack campaigns.
Check If Your Credentials Were Exposed
With over 356,000 credentials in circulation from this single combolist, the chances of being included are real for anyone active online. HEROIC's breach scanner covers more than 400 billion compromised records and provides the fastest way to determine if your email or password has been exposed in this dump or any other known breach. Check your credentials immediately and change any passwords that appear compromised before attackers reach them first.
Breach Breakdown
356,899 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds