The Vuln_cPanels Dump Put 1,655 Stolen Server Logins Online
HEROIC analysts found this file on Telegram on June 29, 2026. A Telegram user uploaded a combolist named Vuln_cPanels containing 1,655 records of email addresses and plaintext passwords tied to cPanel hosting login URLs. Why This Is Dangerous: cPanel is a control panel used to manage web hosting accounts, including websites, email addresses, and databases. A working cPanel login can give an attacker control over an entire website, letting them install malware, redirect visitors, or steal any data stored on that server. What Was Exposed: - Email addresses - Plaintext passwords - cPanel login URLs Why This Matters: If you or your business uses cPanel to manage a website, exposed credentials here could lead to a full website compromise, not just a single account breach. That opens the door to defaced pages, malware distribution to your visitors, and further data theft from anything stored on that server. How a Vulnerable Server Combolist Like This Works: Files labeled Vuln_cPanels typically come from scans of websites running outdated or misconfigured hosting software. Attackers use automated tools to find these vulnerable panels, extract or guess login credentials, and compile the working pairs into a combolist for distribution. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion breached and leaked records. Run a free scan to check your accounts, and if you manage a website, change your hosting passwords as a precaution.
Breach Breakdown
1,655 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds