Breach Intelligence Report 31 Jul 2026

The “USA..” Combolist Quietly Leaked 9,996 Login Credentials

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Combolist usa.. uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 9,996
Source Type Combolist
Origin United States
Password Type plaintext

HEROIC analysts identified a small combolist labeled "usa.." that surfaced on Telegram in May 2026. The file contains 9,996 records, each pairing an email address with a plaintext password and the URL of the site the credentials were used on. The listing is associated with the United States and has been marked as a verified breach. Why the USA.. Combolist Is Dangerous: While 9,996 records is a modest count compared to some dark web dumps, every one of those records is immediately usable by an attacker. Because the passwords are stored in plaintext rather than hashed or encrypted, no cracking is required. Anyone who downloads this file can plug the email and password pairs directly into a script and start testing them against real websites within minutes, and the attached URLs tell them exactly where to try each one first. What Was Exposed in the USA.. Combolist: email addresses used as account usernames, plaintext passwords stored without any protection, and URLs showing which sites or services each login belongs to. Why This Matters Even for a Smaller Leak: A breach of under 10,000 records can feel less alarming than a headline-grabbing million-record dump, but the danger to each individual affected is identical. If your email and password appear in this file, an attacker can attempt credential stuffing against your other accounts, including email, banking, and social media, especially if you have reused that same password anywhere else. Small combolists like this one are also frequently combined with other leaked files, multiplying the risk over time. How a Combolist Like This One Works: A combolist is a plain text file that pairs usernames or email addresses with matching passwords, typically compiled from older breaches, phishing pages, or infected devices and then shared or sold on platforms like Telegram. Unlike a single company's breached database, a combolist can pull from many unrelated sources at once, which is why file names like "usa.." often give little indication of where the data actually originated. Its value to criminals lies entirely in being ready to use immediately, with no additional effort needed to unlock the credentials inside. Check If You Are Affected: Even a leak of this size is worth checking against your own information. HEROIC's free breach scanner searches a database of more than 400 billion exposed records, including combolists like this one, so you can quickly find out whether your email address was part of this leak or any other breach on file.

Breach Breakdown

Domain usa.. uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 31 Jul 2026
Check in 5 seconds

9,996 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,044 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $72.3K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance