Your Login May Be Exposed. The Fresh MOON HQ Dump Leaked 718 Accounts.
HEROIC analysts found a combolist named Fresh MOON HQ HOTS Bh_Zx4 uploaded to Telegram on 2 May 2026. The file contains 718 records, each combining an email address with a plaintext password and a related URL. Why This Is Dangerous: Your login credentials do not need to be cracked or decoded here, they are stored as plain text. Anyone who downloads this file can attempt to sign into any of these 718 accounts right away. What Was Exposed: - Email addresses - Plaintext passwords - URLs connected to each account Why This Matters: Combolists like this one are frequently fed into automated credential-stuffing tools that test each email and password pair against dozens of popular websites at once. If you're in this file and reuse passwords across accounts, an attacker could gain access to your email, banking, or social media without any direct attack on you specifically. How a Combolist Like This Works: The naming pattern here, Fresh MOON HQ HOTS Bh_Zx4, is typical of stealer log and combolist branding used on Telegram, where uploaders label batches to build a reputation for quality among buyers, even when the underlying credentials were gathered from a mix of older sources. Check If You Are Affected: Check your email address against HEROIC's database of more than 400 billion breached records with HEROIC's free breach scanner to see if you were exposed in this leak.
Breach Breakdown
718 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds