The berlin.de Leak: 2,703 Email and Password Pairs Exposed
In June 2026, HEROIC analysts found a combolist titled "berlin.de - 2.703 emails" after it was uploaded by a Telegram user. The file contains 2,703 records tied to the German portal berlin.de, combining email addresses, plaintext passwords, and the URLs those credentials were used on. Why This Is Dangerous: because berlin.de is a regional portal used by residents for local services, the accounts in this file are likely tied to real people's everyday online activity in the Berlin area. With passwords stored in plaintext, anyone who obtains the file can use these credentials immediately. What Was Exposed: email addresses, plaintext passwords, and URLs tied to each account. Why This Matters for berlin.de Users: people often reuse the same password across a local portal account and more sensitive services like email or banking. If any of these 2,703 credential pairs match a password used elsewhere, an attacker could pivot from a low value regional account into a much more damaging account takeover. How Regional Combolists Like This Are Built: combolists focused on a single site, like this one built specifically around berlin.de, are usually created by scraping data tied to a known service or by filtering a larger breach down to just the records relevant to that domain. Sellers package them this way because a targeted list is easier for buyers to use against a specific type of account. Check If You Are Affected: if you have ever registered on berlin.de or a similar regional service, it's worth checking your exposure now. HEROIC's free breach scanner searches more than 400 billion leaked records so you can confirm whether your information was part of this leak and update your password if it was.
Breach Breakdown
2,703 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds