The Vuln_DirectAdmin Leak Exposed 718 US Login Credentials
The Vuln_DirectAdmin Combolist Exposes 718 Login Credentials HEROIC analysts found a combolist labeled "Vuln_DirectAdmin" uploaded to Telegram on July 15, 2026. The file holds 718 records pairing email addresses with plaintext passwords, along with related login URLs. Why This Is Dangerous The naming of this file suggests it may be tied to a known DirectAdmin control panel vulnerability, which attackers can use to harvest hosting account credentials directly from compromised servers. Combined with plaintext passwords, this gives attackers an easy path into any account where the password still works. What Was Exposed Email addressesPlaintext passwordsAssociated URLs Why This Matters Even a small dataset of 718 records can be valuable to attackers running credential stuffing attacks, especially if the underlying accounts control web hosting or server access. A compromised hosting account can be used to deface websites, host malware, or pivot into other connected systems. How a Combolist Works A combolist compiles previously harvested login pairs, username or email plus password, into one file that criminals can run through automated tools that test each pair against multiple websites. These lists are often built from a mix of leaked databases, phishing campaigns, and vulnerability exploits. Check If You Are Affected If you manage hosting accounts or think your credentials might be part of the Vuln_DirectAdmin combolist, HEROIC's free breach scanner checks your email against more than 400 billion leaked records. Scan now and rotate any passwords that may be exposed.
Breach Breakdown
718 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds