The QQ.COM COMBO Data Just Went Public. Here Is What Was Exposed.
HEROIC analysts found the QQ.COM COMBO dataset circulating on Telegram in April 2025. The breach exposed 275,020 records including email addresses, plaintext passwords, and URL data harvested from devices associated with QQ.com accounts and related Chinese platform services.
QQ Account Credentials Open Access to China's Largest Digital Ecosystem
QQ.com is part of Tencent's massive ecosystem, connecting users to WeChat, QQ Music, gaming platforms, and mobile payments. Attackers with stolen QQ credentials can pivot across linked Tencent services, gaining access to financial accounts, communications, and digital content libraries.
What the QQ.COM COMBO Leak Exposed
- Email Addresses
- Plaintext Passwords
- URLs (endpoint context)
How 275,000 QQ Credentials Enable Large-Scale Platform Fraud
With 275,020 records, this QQ.COM COMBO breach represents a significant volume of credentials ready for automated exploitation. Attackers can target linked Tencent services, gaming accounts with valuable in-game assets, and WeChat Pay or QQ Wallet balances associated with these compromised accounts.
How Stealer Log Breaches Work
Stealer logs are produced by malware silently installed on victims' computers. The malware captures usernames, passwords, and browser session data before sending it to criminals, who then package and sell the data on Telegram channels and dark web markets.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches over 400 billion+ leaked records to tell you if your email was part of this or any other stealer log dump. Check your exposure now at no cost.
Breach Breakdown
275,020 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds