The cstone.net Leak: 2,520 Login Emails and Passwords Exposed
HEROIC analysts identified a file titled "cstone.net - 2.520 emails" uploaded to Telegram in June 2026, containing 2,520 email addresses paired with plaintext passwords and login URLs tied to the cstone.net service. Why This Is Dangerous: Because the passwords are stored in plaintext, anyone who downloads this file can try the credentials against other sites immediately, with no cracking required. What Was Exposed: The file contains email addresses, plaintext passwords, and the URLs of the accounts those credentials were used on, all tied to cstone.net. Why This Matters: People frequently reuse passwords between an internet or hosting provider account and their email, banking, or shopping logins. If your credentials are in this file and reused elsewhere, attackers can use credential stuffing to try that same password across other services until one works. How a Combolist Leak Like This Works: A combolist is a plain text file of stolen or scraped login credentials tied to a specific service, usually assembled from a smaller breach or phishing page and then circulated on Telegram before being folded into larger compilations. Check If You Are Affected: If you've used cstone.net or reused a password from it elsewhere, check your exposure today. HEROIC's free breach scanner searches over 400 billion leaked records, including combolists like this one, and tells you instantly if action is needed.
Breach Breakdown
2,520 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds