The ‘900x Neo3690’ Dump: 808 Stolen Logins Hit the Dark Web
HEROIC analysts identified a combolist named "900x USA GOOD TEST Neo3690" uploaded to a Telegram channel on January 23, 2025. The file contains 808 records, each pairing an email address with a plaintext password and the URL the login was used on, packaged under the handle "Neo3690." Why This Is Dangerous: The "GOOD" in this file's name signals the uploader has already filtered out dead logins, leaving only credentials believed to still work. That curation step means a higher share of these 808 records could grant an attacker real access than in a random, untested dump. What Was Exposed: Email addresses. Plaintext passwords. URLs showing which site or service each set of credentials was captured from. Why This Matters: Because this list has reportedly been pre-checked, anyone whose login appears here faces a more immediate risk of account takeover than usual. A single working password can be reused by an attacker to access email, financial accounts, or any other service tied to that same address. How a Combolist Like This Gets Made: Uploaders who tag their releases with handles like "Neo3690" are often repeat sellers on Telegram, building a reputation by testing stolen credentials in bulk and releasing smaller, labeled batches like this one to buyers looking for reliably working logins. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records. Run a scan to see if your credentials are among the 808 in this file before someone else tries them first.
Breach Breakdown
808 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds