The ‘500k 1’ Combolist Means 472,875 Passwords Are Now Public
On July 27, 2026, HEROIC analysts flagged a combolist named "500k 1" that a Telegram user uploaded, exposing 472,875 records made up of email addresses, plaintext passwords, and associated URLs. Why This Is Dangerous: A combolist of this size gives attackers hundreds of thousands of ready-to-use login pairs in one file. There is no cracking or guessing required. The passwords are stored in plaintext, so anyone who downloads the list can start testing them against other websites immediately. What Was Exposed: The data includes email addresses, plaintext passwords, and the URLs tied to each login. Combolists like this one are typically compiled from a mix of older breaches and stealer logs, then repackaged for reuse. Why This Matters: With 472,875 pairs in a single file, this list is built for automated attacks. Criminals load combolists into credential stuffing tools that test each email and password combination against banking sites, email providers, and social media platforms in bulk, hoping password reuse does the rest of the work for them. How a Combolist Like This Works: A combolist is a compiled file of email or username and password pairs, usually pulled from multiple older breaches, stealer logs, or previous leaks, then merged into one list. Unlike a single stealer log, a combolist is built for scale and speed. Attackers do not need to know where the data originally came from, they just need it to be current enough that some percentage of the logins still work. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including combolists like this one. Run a scan today to see if your credentials are part of this leak.
Breach Breakdown
472,875 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds