The 163.cn Email Leak Happened in June. It Just Went Public.
The credentials in this leak are dated June 10, 2026, but HEROIC analysts didn't spot the combolist, labeled "163.cn - 785 emails," circulating on a Telegram channel until weeks later. The file contains 785 records, each pairing an email address on the 163.cn domain with a plaintext password and an associated URL. Why the Gap Between Leak and Discovery Matters Whenever there's a stretch of time between when data like this is actually stolen and when it turns up somewhere researchers can see it, that gap usually means someone already had access and possibly already used it. A password sitting in plaintext for weeks before wider circulation gives an attacker a real head start over the people it belongs to. What Was Exposed in the 163.cn Combolist 163.cn email addresses Plaintext passwords Associated URLs Why This Matters Even a list of 785 records is enough for credential stuffing, where attackers test each email and password pair against banking sites, other email providers, and social media accounts. If you reused your 163.cn password anywhere else, the risk extends to account takeover, identity theft, and financial fraud well beyond your email inbox. Check If You Are Affected If you use a 163.cn email address, or reuse the same password across multiple accounts, check now rather than waiting for the next dump to surface. HEROIC's free breach scanner searches more than 400 billion exposed records, so you can find out quickly and change any passwords that may already be circulating.
Breach Breakdown
785 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds