The “567” Dump: 563 Stolen Login Credentials Hit the Dark Web
The "567" Combolist Exposed 563 Login Credentials
On September 28, 2025, HEROIC's threat intelligence analysts identified a combolist labeled simply "567" being shared by a user on Telegram. The verified file contains 563 records, each pairing an email address with a plaintext password and the URL of the login page it works on. Most of the affected accounts are tied to the United States.
Why This Is Dangerous
The passwords in this file are stored in plaintext, meaning there is no encryption standing between an attacker and a usable login. Each record also includes the exact URL where that email and password pair works, so there is no guessing involved either. An attacker with this file has the account, the password, and the destination all in one place, which is close to the minimum effort required to break into someone's account.
What Was Exposed in the "567" Dump
- Email addresses
- Plaintext passwords
- URLs linking each credential pair to its login page
Why a Small Leak Still Puts You at Risk
A file with 563 records will not make international headlines, but that does not make it any less serious for the people in it. If your password here matches one you use elsewhere, attackers can attempt credential stuffing against your email, banking, or social media accounts. A single working match is often enough to trigger account takeover or financial fraud, regardless of how small the original list was.
How a Bare-Named Combolist Like This One Gets Made
Files labeled with nothing more than a number or short code are usually informal batches, credentials pulled together from older breaches, phishing pages, or malware infections and combined into a single list without much branding. Sellers or distributors often name them quickly before uploading, since the value is in the working logins, not the presentation. Once assembled, lists like this circulate through Telegram channels and dark web forums, where they are shared or sold to anyone looking for accounts to test.
Check If Your Email Was in the "567" Leak
You do not have to wonder whether you are one of the 563 people in this file. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including combolists like this one, and tells you immediately if you have been exposed. If a match turns up, change that password right away, and anywhere else you used it.
Breach Breakdown
563 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds