Imagine 477,530 Passwords for Sale: Inside the USA Combo VIP Leak
Picture a single file sitting in a Telegram channel, quietly changing hands between strangers, each one holding the same 477,530 email and password pairs. That is what HEROIC analysts found in June 2026 inside a dump called "USA Combo VIP," a large collection of American email credentials complete with plaintext passwords and the exact URLs those logins were used on. Unlike a corporate breach announcement, no company ever reported this incident, because the data did not come from a hacked server, it came from malware sitting on individual victims' own computers.
Why This Is Dangerous
At nearly half a million records, this file gives whoever holds it a large, ready-made target list rather than a handful of scattered leads. Because the passwords are stored in plaintext and each one is paired with the exact login page it belongs to, there is no cracking or guesswork required, an attacker can attempt to sign in immediately. The "VIP" label attached to the file suggests it may have been marketed as a premium or curated batch, the kind of detail sellers use to charge more for stolen access.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs of the associated login pages
Why This Matters
Email accounts sit at the center of most people's online lives, used to verify identity and reset passwords for banking, shopping, and social media. A leak of this size raises the odds that any individual American whose email was captured faces a real risk of account takeover, especially if the password was never changed since it was stolen. Reused passwords make the danger worse still, since attackers routinely run large batches like this one through credential stuffing attempts against banks, retailers, and other popular services.
How Stealer Logs Work
Stealer logs come from malware that infects a device, typically through a pirated download, a fake software update, or a malicious attachment, then quietly harvests saved browser passwords, autofill data, and active login sessions. Criminals collect these logs from thousands of infected machines and combine them into large combo files like this one, sometimes filtering by country to create a more targeted product. Files of this scale are traded and sold across Telegram channels and dark web marketplaces, often priced according to how fresh or well-organized the data is.
Check If You Are Affected
If you have a US-based email account, it is worth checking whether your credentials appear in this leak or any other. HEROIC's free breach scanner checks your email address against a database of more than 400 billion leaked records, including large stealer log dumps like this one, so you can see your exposure and secure your accounts before someone else uses them.
Breach Breakdown
477,530 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds