The dont-contact.us Leak Put 4,857 Email and Password Pairs Online
HEROIC analysts discovered a combolist connected to the dont-contact.us domain, uploaded by a Telegram user on June 10, 2026. It contains 4,857 records, each one an email address paired with a plaintext password and the URL that login was used on. Why This Is Dangerous: There is nothing to decode or guess here. Each record hands an attacker a complete, working login: the email, the exact password, and the site it opens. That is everything needed to walk straight into an account. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each credential pair Why This Matters: With 4,857 working logins in circulation, the real danger is credential stuffing, where attackers automatically test each email and password pair against banking sites, email providers, and social platforms. Anyone who reused this password elsewhere faces a real risk of account takeover, identity theft, or financial fraud stemming from a single leaked file. How a Combolist Like This Works: A combolist is a compiled list of stolen or leaked email and password combinations, often gathered from previous breaches or malware infections and grouped by the site each pair unlocks. These files are cheap to obtain and trade on Telegram, and attackers can run the entire list through automated login tools within hours of getting it. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this dont-contact.us leak. Run a scan now to see if your credentials are part of it.
Breach Breakdown
4,857 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds