Our Analysts Found the TrinityF0rce Combolist With 49,998 Logins
HEROIC analysts discovered a large combolist named "TrinityF0rce" circulating on Telegram, uploaded August 29, 2025. The file contains 49,998 records, each pairing an email address with a plaintext password and the URL of the site it unlocks, making it one of the larger files HEROIC has tracked from this channel. Why This Is Dangerous: At nearly 50,000 records, this file gives an attacker a large, ready-made list to run through automated login attempts across banking, email, retail, and social media sites, with every password stored in plain, unencrypted text. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each login Why This Matters: The bigger the combolist, the more efficient large-scale credential stuffing becomes for attackers, who use automated tools to test all 49,998 pairs against hundreds of popular websites in minutes. Anyone whose password shows up here is at meaningfully higher risk of account takeover, identity theft, or financial fraud. How a Combolist Like This Works: Large combolists like TrinityF0rce are usually stitched together from multiple smaller breaches, phishing operations, and malware logs over time, then merged, deduplicated, and released as one file. The name itself is often just a branding choice by whoever compiled and uploaded it. Check If You Are Affected: With a file this size, the odds that your email is included are worth taking seriously. Run a free check against this leak and HEROIC's database of more than 400 billion exposed records using HEROIC's breach scanner, and change any password you find reused.
Breach Breakdown
49,998 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds