U.S. Inboxes at Risk as MailAccess Combos 5 Leaks 2,896 Logins
HEROIC threat researchers have identified MailAccess Combos 5, the fifth volume in a recurring stealer log series, uploaded to a public Telegram channel in June 2026. This installment contains 2,896 records targeting U.S. email users, with each entry pairing an email address with a plaintext password and the URL of the service where the credentials were captured. The continued production of new volumes confirms that the operation behind this series remains active and continues to compromise fresh victims.
For U.S. internet users, this fifth release means the pool of exposed email credentials from this single operation now spans thousands of accounts across multiple dumps, creating a growing risk for anyone whose device may have been infected by infostealer malware.
Why Plaintext Passwords in a Series Compound the Danger
Each of the 2,896 passwords in MailAccess Combos 5 is stored in plaintext, identical to the format used in previous installments. There is no hashing, no salting, and no encryption. Every credential is immediately usable, and the consistency of the format across the series tells attackers exactly what to expect and how to process the data at scale.
The serial nature of these releases creates compounding risk. Attackers who automated their exploitation pipeline for Combos 1 through 4 can process Combos 5 instantly upon download. There is zero ramp-up time between release and exploitation.
For victims whose credentials appear in this dump, the plaintext format means the threat is immediate. Their email accounts can be accessed, their messages read, and their linked services compromised within minutes of an attacker downloading the file.
What Was Exposed in the MailAccess Combos 5 Dump
- Email Addresses — U.S.-based email accounts curated for inbox access, representing high-value targets for account takeover, business email compromise, and identity theft operations.
- Plaintext Passwords — Unencrypted passwords harvested directly from infected devices, formatted for instant exploitation in automated credential testing frameworks.
- URLs — Login endpoints and service addresses where credentials were originally entered, enabling attackers to bypass guesswork and directly target each victim's known accounts.
Why Volume 5 Signals a Persistent Threat to U.S. Users
Five consecutive releases in the MailAccess Combos series demonstrate an operation with staying power. This is not a one-off data dump but a sustained campaign that generates and distributes new credential batches at regular intervals. The 2,896 records in this installment add to a cumulative total that likely exceeds 14,000 compromised email accounts across all five known volumes.
U.S. email users face particular exposure because the MailAccess series appears to focus on American credential data. The targeted nature of the curation means that the email providers, banking services, and online platforms most commonly used by Americans are disproportionately represented in the data.
Each new volume also refreshes the dataset available to credential stuffing operators. Even victims from earlier releases who changed their passwords may find that other accounts — ones they forgot about or did not know were compromised — remain vulnerable to the URL data included in these dumps.
How the MailAccess Pipeline Operates
The MailAccess Combos series is powered by the same infrastructure that drives the broader stealer log ecosystem. Infostealer malware infects devices through phishing campaigns, malicious advertisements, and trojanized software downloads. The malware silently extracts credentials from browsers, email clients, and other applications, then transmits the data to collection servers.
From there, specialized operators sort the raw logs by type and region. Email credentials are separated into "mail access" collections because of their premium value in the underground economy. These sorted datasets are then divided into manageable batches and released as numbered volumes through dedicated Telegram channels.
The business model is straightforward: regular, numbered releases build a subscriber base of threat actors who depend on fresh credential data for their own fraud operations. The MailAccess Combos channel likely serves hundreds or thousands of such subscribers who act on each new release within hours of publication.
Check If Your Credentials Were Exposed
With five volumes now released in this series, the probability of any individual U.S. email user appearing in the combined dataset continues to grow. Whether your credentials were captured this month or months ago, the data remains exploitable until you change your passwords.
HEROIC provides a free breach scanner that checks your email against more than 400 billion records from known breaches and stealer log distributions worldwide. Enter your email address to find out if your credentials appear in MailAccess Combos 5 or any other compromised dataset. If found, change your password immediately, check your email account for unauthorized forwarding rules or connected applications, and enable two-factor authentication on every account that supports it.
Breach Breakdown
2,896 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds