The Abv.bg Combolist Leaked 1,948 Email and Password Pairs
In December 2022, HEROIC analysts identified a combolist file tied to abv.bg, a Bulgarian webmail and portal service, uploaded to a Telegram channel. The file contained 1,948 records pairing email addresses with plaintext passwords and related URLs. Why This Is Dangerous: Webmail accounts like these are often the recovery point for banking, shopping, and social media logins. Because the passwords in this file are stored in plaintext, anyone who obtains it can use the credentials immediately, and a compromised inbox can be used to reset passwords on other services. What Was Exposed: - Email addresses - Plaintext passwords - URLs linked to each account Why This Matters: This is a small list, under 2,000 records, but each one represents a real account. If someone in this list reused their abv.bg password anywhere else, an attacker can use credential stuffing to break into those other accounts, risking financial fraud and identity theft. How a Combolist Like This Works: Lists focused on a specific email provider are usually built by filtering larger stealer malware or breach datasets down to accounts matching that domain, making them easier for buyers to target with follow-up phishing or account takeover attempts. Check If You Are Affected: Use HEROIC's free breach scanner to check your email against more than 400 billion exposed records and see whether your credentials appear in this or any other leak.
Breach Breakdown
1,948 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds