The Valorant Combolist: 2,905 Stolen Logins Hit the Dark Web
HEROIC analysts identified this stealer log on 18-Jan-2023. The breach exposed 2,905 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as 3k Valorant Site target Combolist uploaded by a Telegram User.
Why This Is Dangerous
Gaming account credentials are high-value targets because players often link credit cards to their accounts and accumulate in-game currency and rare items. With a plaintext password and matching email, an attacker can take over an account, lock out the original owner, and sell the account or its digital assets.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
Stolen gaming credentials are frequently reused to access email accounts and other services where the same password was used. This can lead to account takeover, identity theft, and financial fraud well beyond the original gaming platform. Credential stuffing tools make it easy for attackers to test thousands of logins quickly.
How Stealer Logs Work
Stealer malware targets gaming platforms specifically by capturing credentials entered into game launchers and browsers. Once a device is infected, the malware copies login data and sends it to the attacker. These credential files are then shared across private Telegram channels where cybercriminals use them for account takeover and resale.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records from known breaches. Search your email address now to find out if your credentials appear in this breach or others. The scan is free and takes seconds.
Breach Breakdown
2,905 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds