The Good_cPanelWebmail Leak: Two Stolen Login Credentials Surface
HEROIC analysts found a combolist called Good_cPanelWebmail that a Telegram user uploaded on May 21, 2026. The file is very small, containing just 2 records, each pairing an email address with a plaintext password and the URL tied to a cPanel webmail login. Why This Is Dangerous: Even with only two records, both are complete, working logins. Each one hands an attacker the email, its exact plaintext password, and the specific webmail panel it unlocks, with nothing left to guess. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each cPanel webmail login Why This Matters: cPanel webmail access often sits behind hosting accounts that control entire websites and domains. If either of these two credentials was reused elsewhere, an attacker could pivot from webmail access into broader account takeover, and if the underlying hosting account is compromised, into site defacement or further data theft. How This Combolist Was Built: A combolist compiles stolen or leaked login pairs, in this case scraped or harvested from cPanel-based webmail systems, and organizes them by the URL each credential works on. Even tiny files like this one circulate on Telegram, often as proof of a larger stash a seller is offering. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this Good_cPanelWebmail leak. Run a free scan now to see if your credentials are part of it.
Breach Breakdown
2 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds