Your Data May Be Exposed. The ‘whm 2’ Leak Holds 8,899 Login Pairs.
HEROIC analysts identified a combolist called "whm 2" that a Telegram user uploaded on July 28, 2026. WHM, or WebHost Manager, is a server control panel used by hosting providers, and this file contains 8,899 records, each pairing an email address with a plaintext password and the URL that login was used on. Why This Is Dangerous: Each of these 8,899 records is a complete, working login. There is no cracking or guessing involved, the attacker gets the email, the exact password, and the site it opens, all in one line. What Was Exposed: - Email addresses - Plaintext passwords - URLs tied to each credential pair, including WHM server panel logins Why This Matters: Credentials tied to server control panels like WHM can potentially expose entire websites and the accounts hosted on them, not just a single inbox. With 8,899 login pairs in circulation, the risk includes credential stuffing against unrelated personal accounts as well as targeted attacks on any hosting infrastructure tied to this file. How This Combolist Was Built: A combolist compiles stolen or leaked login pairs, often gathered from breaches, phishing, or malware infections targeting server administrators and hosting customers, then organizes them by the panel or site each credential works on. Files like "whm 2" are traded on Telegram because hosting-level access can be worth more to attackers than a single personal account. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including this leak. Run a free scan now to see if your credentials are part of it.
Breach Breakdown
8,899 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds