The Vuln_cPanels Leak: 1,910 Hosting Logins Exposed Online
HEROIC analysts found a combolist titled "Vuln_cPanels" uploaded to Telegram on July 15, 2026. The file contains 1,910 records, each pairing an email address with a plaintext password and the login URL tied to a cPanel hosting control panel. Why This Is Dangerous: cPanel logins control entire websites, including files, databases, and email accounts hosted on that server. A working credential here can hand an attacker far more than one account, it can hand over an entire website. What Was Exposed: - Email addresses - Plaintext passwords - URLs pointing to cPanel login pages Why This Matters: If you or your business manages hosting through cPanel, a leaked login here could let an attacker deface your website, steal customer data, or use your server to launch further attacks, all from one compromised account. The same password, if reused, also opens the door to credential stuffing on personal accounts. How a Combolist Like This Works: Combolists targeting cPanel are usually built by scanning the internet for exposed hosting control panels, then testing leaked or common passwords against them until a working login is found. Confirmed matches are compiled into a file like this one. Check If You Are Affected: If you manage a website or hosting account, check your email now against this leak and HEROIC's database of more than 400 billion exposed records using HEROIC's free breach scanner, and change your cPanel password immediately if you find a match.
Breach Breakdown
1,910 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds