The Vuln_cPanels Dump: 562 Hosting Account Logins Hit Telegram
HEROIC analysts found a file named Vuln_cPanels uploaded by a Telegram user in June 2026. It contains 562 records of email addresses and plaintext passwords tied to cPanel, one of the most widely used web hosting control panels. Why This Is Dangerous: A working cPanel login gives an attacker direct access to a hosting account, including its websites, files, databases, and often its email accounts. With 562 sets of credentials listed here, that is 562 potential points of entry into hosted infrastructure, not just individual mailboxes. What Was Exposed: - Email addresses linked to hosting accounts - Plaintext passwords - URLs of the affected cPanel login pages Why This Matters: If these credentials still work, an attacker could deface websites, install malware, steal customer data, or use the hosting account to launch further attacks. Anyone who manages a website through one of these accounts, or whose site shares a server with one, could be affected indirectly. How This Combolist Works: Lists like Vuln_cPanels are usually built by scanning the internet for hosting panels and testing common or previously leaked passwords against them. Any successful logins are compiled into a file and labeled by the type of panel they unlock, making it easy for a buyer to know exactly what kind of access they are purchasing. Check If You Are Affected: If you run a website or manage hosting accounts, check your credentials against HEROIC's free breach scanner, which covers more than 400 billion exposed records.
Breach Breakdown
562 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds