The randwater.co.za Leak: 1,405 Login Credentials Exposed
HEROIC analysts identified a file titled "randwater.co.za - 1.405 emails" uploaded to Telegram in June 2026, containing 1,405 email addresses paired with plaintext passwords and login URLs tied to the randwater.co.za service, a South African utility provider. Why This Is Dangerous: The passwords in this file are stored as plaintext, meaning anyone who downloads it can start trying the credentials on other sites right away, with no cracking needed. What Was Exposed: The file contains email addresses, plaintext passwords, and the URLs of the accounts those credentials were used on, all connected to randwater.co.za. Why This Matters: Utility provider accounts are often used to store billing and personal contact details, and the login credentials are frequently reused across email and banking accounts. If your information is in this file and the password was reused elsewhere, attackers can use credential stuffing to access those other accounts too. How a Combolist Leak Like This Works: A combolist bundles login credentials tied to a specific site into a single plain text file, usually pulled from a smaller breach or phishing campaign and then shared on Telegram before being merged into larger compilations. Check If You Are Affected: If you've used randwater.co.za or reused a password from it, check your exposure now. HEROIC's free breach scanner searches over 400 billion leaked records, including combolists like this one, and shows you instantly whether you need to act.
Breach Breakdown
1,405 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds