The Logins_Ftp Leak Happened Months Ago. The Data Just Went Public.
The Logins_Ftp Combolist Goes Public Months After It Was First Collected
HEROIC analysts identified a combolist named Logins_Ftp circulating on Telegram, tied to data originally collected in February 2026. The file contains 601 records pairing email addresses with plaintext passwords and the URLs each credential was used on.
Why the Delay Between Collection and Exposure Matters
Months passed between when this data was gathered and when it started circulating publicly. That gap gives account holders time to change a password, but only if they know to look. Until then, the credentials in this file remain valid and usable by anyone who gets hold of them.
What Was Exposed in the Logins_Ftp Leak
- Email addresses
- Plaintext passwords
- URLs tied to each credential pair
Why This Matters
A combolist that has quietly aged for months before going public can still be highly effective for credential stuffing, since many people never change a password unless they know it was exposed. That opens the door to account takeover, identity theft, and financial fraud for anyone who reused these credentials elsewhere.
How a Combolist Like Logins_Ftp Gets Assembled
Combolists are typically built from credentials gathered through stealer logs or older breaches, then organized into a single file of matching email and password pairs before being shared in Telegram groups, sometimes months after the underlying data was first collected.
Check If You Are Affected
Use HEROIC's free breach scanner to check your email against more than 400 billion leaked records, including the Logins_Ftp file, and find out if your password needs to change now.
Breach Breakdown
601 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds