USA UHQ Combo Leak Means 514,554 Accounts Are Ready to Steal
HEROIC analysts flagged a large stealer log collection titled "619k USA UHQ Combo" that appeared on a Telegram channel in May 2023. The dataset contains 514,554 verified compromised records, each pairing an email address with a plaintext password and the URL where the credentials were used. The "USA" and "UHQ" (ultra-high quality) labels indicate the collection specifically targets American users and was marketed as containing fresh, active credentials.
Why Plaintext Passwords Mean Instant Account Takeover
None of the 514,554 passwords in this collection are encrypted or hashed. Every single one is stored exactly as the victim typed it, in fully readable plaintext. An attacker does not need to run password-cracking tools, rent computing power, or spend any time decoding the data. They can log into compromised accounts within seconds of downloading the file.
The "UHQ" label compounds the threat. In Telegram credential markets, this designation tells buyers the data has been filtered for quality — meaning dead emails and invalid logins have been removed. What remains is a curated list of working credentials, dramatically increasing the success rate of any attack that uses this data.
What Was Exposed in the USA UHQ Combo Dump
- Email Addresses — Over half a million American email addresses that double as login identifiers and targets for phishing, business email compromise, and identity theft.
- Plaintext Passwords — Readable, unprocessed passwords stolen directly from infected devices, giving attackers immediate access without any technical barriers.
- URLs — The specific websites and platforms where each credential set was used, providing a detailed blueprint for targeted account takeover campaigns.
Why Half a Million American Credentials Demand Attention
A dataset of 514,554 credentials concentrated on American users represents a serious threat to domestic financial systems, corporate networks, and personal accounts. U.S.-based email addresses are frequently linked to banking services, healthcare portals, government accounts, and workplace platforms — all high-value targets for attackers.
Credential-stuffing campaigns thrive on volume and geographic targeting. When attackers know a credential set belongs to an American user, they can prioritize U.S.-specific services such as major banks, healthcare systems, tax platforms, and retail chains. With password reuse rates exceeding 60%, each of these half-million credentials could unlock access to multiple accounts per victim, multiplying the damage many times over.
How Stealer Logs Feed the Combo List Economy
Combo lists like this one are assembled from thousands of individual infostealer infections. Malware variants such as RedLine, Lumma, and Vidar quietly extract saved credentials from browsers, email clients, and applications on infected machines. The raw logs from each device are then merged, deduplicated, and sorted by country or service type to create targeted combo lists.
The "619k" in the collection name reflects the original volume before deduplication, while the verified count of 514,554 represents unique, actionable records. These curated combo lists command higher prices and wider distribution on Telegram because they save attackers the work of cleaning raw data. Once shared, they are downloaded, resold, and recycled through the criminal ecosystem for months or even years.
Check If Your Credentials Appear in This Leak
If you are a U.S.-based internet user who has saved passwords in a browser or used autofill on any website, your credentials may be part of the USA UHQ Combo collection. The breadth of this dump means it likely spans banking, social media, email, shopping, and professional services.
Use HEROIC's free breach scanner to check whether your email address or passwords appear in this dump or among our database of 400B+ compromised records. Acting quickly — changing compromised passwords and enabling two-factor authentication — is the best defense against the credential-stuffing attacks that follow leaks of this magnitude.
Breach Breakdown
514,554 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds