Researchers Link Zoho Mail Combolist to 31 Exposed Login Pairs
In July 2026, HEROIC analysts identified a combolist referencing "Zoho Mail" uploaded to a Telegram channel. The file contained 31 records pairing email addresses with plaintext passwords and associated URLs. Why the Zoho Mail Combolist Is Dangerous: even a small file like this one puts real accounts at risk. Because the passwords are stored in plaintext, anyone who downloads the list can log in immediately, no technical skill or password cracking required. What Was Exposed: email addresses, plaintext passwords, and the URLs tied to each login. Why This Matters: email accounts are often the key to resetting passwords everywhere else, so a compromised email login can quickly turn into a much bigger problem. If any of the 31 people in this list reused their password, an attacker could use their email account to reset logins for banking, shopping, or social media accounts. How a Combolist Works: a combolist compiles email or username and password pairs from a mix of sources, including older breaches, phishing pages, and malware infections, into a single list criminals can run through automated login tools. The Zoho Mail combolist fits this pattern, bundling 31 email and password combinations along with the URLs they were tied to. Check If You Are Affected: HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records. Run a free check to see if your Zoho Mail or any other account has been exposed in this or another breach.
Breach Breakdown
31 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds