The D1.umn.edu Leak: 15,918 University Passwords Exposed
In June 2026, HEROIC analysts found a combolist file referencing d1.umn.edu, a University of Minnesota subdomain, that had been uploaded to a Telegram channel. The file contained 15,918 records pairing university email addresses with plaintext passwords and the URLs each pair was tied to. Why This Is Dangerous: University accounts often provide access to student records, financial aid information, campus payment systems, and personal data, making them valuable targets. Because the passwords in this file are stored in plaintext, anyone who obtains it can use the credentials immediately without needing to crack anything. What Was Exposed: - University email addresses - Plaintext passwords - URLs linked to each account Why This Matters: Students and staff often reuse university credentials for personal email, banking, or shopping accounts. If a password in this list matches one used elsewhere, attackers can use credential stuffing to break into those other accounts, leading to financial fraud, identity theft, or unauthorized access to sensitive academic and personal records. How a Combolist Like This Works: These lists are typically built by filtering larger stealer malware dumps or old breach data for a specific domain, in this case a university subdomain, to make the credentials more useful for targeted attacks against that institution's community. Check If You Are Affected: Run a free scan with HEROIC's breach scanner, checking your email against more than 400 billion leaked records, to see if your university or personal credentials appear in this or any other exposed dataset.
Breach Breakdown
15,918 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds