Your Credentials May Be Exposed: DE New 0818 Leak Hit 16,389 Accounts
HEROIC analysts identified a combolist called DE New 0818, uploaded to a Telegram channel and dated February 24, 2023. The file contains 16,389 records, each pairing an email address with a plaintext password and the URL that login was used on. Why This Is Dangerous: A working email and password pair removes the guesswork for an attacker. Instead of trying to break into an account, they can log in directly using the credentials in this file, and the matching URL tells them exactly which site to target. What Was Exposed: Each of the 16,389 records in this file contains three fields. - Email addresses - Plaintext passwords - URLs showing which site each login belongs to Why This Matters: A file of this size gives attackers real scale to work with for credential stuffing, testing the same stolen password across multiple sites in hopes it was reused. Anyone in this file faces increased risk of account takeover, and from there, financial fraud or identity theft. How a Combolist Like This Works: New in a combolist's name usually signals freshly compiled data, often assembled from recent stealer log infections or smaller breaches and grouped together before distribution. Labeling a file new also makes it more attractive to buyers, since fresher credentials are more likely to still be active. Check If You Are Affected: Use HEROIC's free breach scanner, which checks against more than 400 billion leaked records, to see if your email is among the 16,389 exposed in the DE New 0818 file.
Breach Breakdown
16,389 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds