Dark Web Combo List
Designed for security-conscious consumers and website owners, this guide helps you verify possible credential exposure.
A dark web combo list is a machine-readable file of username-and-password pairs that automated credential-stuffing tools can test against login pages[1]. A match does not prove the target site was breached[2]; if alerted, change reused or similar passwords, enable multi-factor authentication[3], and check exposure through Have I Been Pwned without accessing stolen credentials[4].
Reported Combo List Incidents
- Date
- January 17, 2019
- Source
- Collection #1
- Count
- 2,692,818,238
- Provenance
- Confirmed
- Confidence
- Confirmed
- Date
- December 2025
- Source
- FBI Report
- Count
- 5,100 complaints
- Provenance
- Confirmed
- Confidence
- Confirmed
- Date
- November 10-13, 2025
- Source
- Operation Endgame
- Count
- Millions of credentials
- Provenance
- Confirmed
- Confidence
- Confirmed
- Date
- Depends on source
- Source
- Various
- Count
- 38,484,088
- Provenance
- Alleged
- Confidence
- Alleged
- Date
- Depends on context
- Source
- Infostealer
- Count
- Depends on attack
- Provenance
- Unverifiable
- Confidence
- Unverifiable

What Is a Dark Web Combo List?
A dark web combo list is a collection of username and password pairs, typically compiled from various data breaches, phishing attacks, or malware logs. The term “combo” refers to the combination of credentials that can be used together to gain access to user accounts. It's essential to understand that just because a credential appears on a combo list, it does not necessarily mean that the specific service from which the credentials originate has been breached. This distinction is crucial, as credential stuffing attacks involve using known username-password pairs obtained from one site against unrelated services[2].
The formatting of combo lists can vary widely. For example, a single entry might look like this: [email protected]:••••••••, where the email address is paired with a password that has been redacted for security reasons. The inconsistencies in formatting can include different delimiters such as colons, semicolons, and spaces[5].
Combo lists can contain millions of entries; for instance, Collection #1, reported on January 17, 2019, included over 2.6 billion rows, with approximately 1.16 billion unique email-password combinations[5]. This vast amount of data makes it a valuable resource for cybercriminals, who can use these lists to perform credential stuffing attacks, potentially leading to account takeovers if users have reused passwords across multiple sites[2].
To mitigate risks, users are advised to employ unique passwords for different accounts and enable multi-factor authentication where available[3]. Regularly checking for potential exposure through services like Have I Been Pwned can also help users stay informed about their credentials' safety without directly accessing any compromised data[4].
Combo List Structure and Key Terms
Understanding the structure of a combo list is essential for identifying potential risks associated with credential exposure. A combo list typically includes fields such as email, username, password, source domain, URL, and capture date. The following table outlines common fields found in these lists:
| Field | Description |
|---|---|
| The email address associated with the account, often used for login. | |
| Username | The unique identifier for the account, which may differ from the email address. |
| Password | The user's password, which may be stored in plaintext or hashed format. |
| Source Domain | The website or service from which the credentials were obtained. |
| URL | A link to the login page of the source domain. |
| Capture Date | The date on which the data was captured or leaked. |
Passwords can be found in either plaintext or hashed formats. Plaintext passwords are straightforward and can be used directly, whereas hashed passwords require decryption to be usable. It is crucial to distinguish between validated "hits" and untested credentials. A validated hit indicates that the username-password combination has been successfully tested against a login page, while untested credentials have not been verified and may not work.
Here are sanitized examples of how entries might appear in a combo list:
- [email protected]:password123
- username:hashed_password_abc123
In these examples, the first entry shows a plaintext password, while the second entry indicates the use of a hash. This distinction is vital for assessing the potential risk associated with each entry.
It is important to note that a combo list match does not confirm that the associated website has been breached. Credential stuffing attacks often exploit username-password pairs gathered from one site to access unrelated services[2]. Understanding these terms and structures helps users better navigate the risks of credential exposure and take appropriate action to secure their accounts.
Publicly Reported Combo List Incidents and Alerts
We compiled a date-stamped index of publicly reported combo list incidents, focusing on reputable sources to provide clarity on the extent of credential exposure. The table below outlines significant incidents, including the reported name, publication date, alleged record count, affected service or domain, source, and verification status.
| Date | Reported Name | Alleged Record Count | Affected Service/Domain | Source | Verification Status |
|---|---|---|---|---|---|
| January 17, 2019 | Collection #1 | 2,692,818,238 | Various | The 773 Million Record "Collection #1" Data Breach[5] | Confirmed |
| December 2025 | FBI Report | 5,100 complaints | Banking institutions | Justice Department Announcement[6] | Confirmed |
| November 10-13, 2025 | Operation Endgame | Millions of records | Various | End of the Game for Cybercrime Infrastructure[7] | Confirmed |
| Variable Dates | Alleged Wordlists | 38,484,088 | Various | United States v. Austad and Stokes Criminal Complaint[1] | Alleged |
| Variable Context | Infostealer Outputs | Depends on attack | Various | Microsoft Digital Defense Report 2025[8] | Unverifiable |
The data presented illustrates the serious nature of combo lists and their potential to facilitate credential stuffing attacks. For instance, Collection #1 is one of the largest reported breaches, comprising over 2.6 billion rows, which includes a staggering number of unique email-password combinations[5]. This incident underscores the importance of being vigilant about password reuse across different services.
It is worth noting that the verification status is crucial when evaluating the credibility of reported incidents. For example, while the FBI report on bank-account takeovers is confirmed, other claims, such as those regarding various alleged wordlists, may not have been substantiated and should be treated with caution[1].
Users should remain aware that a match with a combo list does not indicate that the tested website was breached; rather, it highlights the risks associated with credential reuse[2]. Regularly monitoring for potential exposure through services like Have I Been Pwned is advisable, as is the implementation of multi-factor authentication to enhance account security[4][3].
Combo Lists vs. Database Breaches, Credential Dumps, and Infostealer Logs
Understanding the differences between combo lists, database breaches, credential dumps, and infostealer logs is crucial for assessing the security implications of credential exposure. The following table compares their origins, typical fields, reliability, and security implications:
| Category | Origin | Typical Fields | Reliability | Security Implications |
|---|---|---|---|---|
| Combo Lists | Compiled from various data breaches, often outdated, and combined from multiple sources. | Username, password, source domain, capture date | Variable; often contains stale data from multiple incidents[1][5]. | High risk if reused passwords are used across services; does not confirm a new breach[2]. |
| Database Breaches | Direct leaks from specific services or websites, usually confirmed incidents. | Username, password, email, source domain, timestamp | High; data is usually verified from the source[5]. | Indicates a confirmed breach; immediate action required to secure accounts. |
| Credential Dumps | Collections of leaked credentials typically from malware or phishing attacks. | Username, password, email, and sometimes additional personal information. | Variable; depends on the source of the dump[2]. | High risk of account takeover if passwords are reused; immediate action recommended. |
| Infostealer Logs | Generated by malware that captures credentials in real-time from infected devices. | Browser passwords, cookies, session tokens, financial data, device context[8]. | High; often contains up-to-date credentials and sensitive information. | Very high risk; immediate action needed to mitigate exposure and secure accounts. |
Combo lists often combine old data from various incidents, making them less reliable than direct database breaches or infostealer logs. Infostealer logs can provide newer credentials, URLs, cookies, or device information, presenting a more immediate threat. For instance, a user might receive a combo-list alert involving an old password that was previously compromised but has not been reused on any current accounts. This scenario illustrates why a combo-list alert does not necessarily indicate a fresh breach; it simply highlights the risks associated with password reuse across different platforms.
Where Combo Lists Circulate: Dark Web, Telegram, and Onion Links
Combo lists circulate in various environments, primarily on dark web forums, paste sites, and messaging platforms like Telegram. These platforms often serve as hubs for cybercriminals to share and sell stolen credentials, leveraging the anonymity provided by the Tor network. Dark web forums may feature discussions about credential stuffing attacks and the sale of compromised accounts, while paste sites allow users to upload and share data dumps containing combo lists. Messaging channels, including Telegram, are increasingly used for real-time communication regarding ongoing attacks and the bulk sale of stolen credentials[1].
Onion links refer to web addresses that end with the .onion extension, which indicates they are accessible only through the Tor network. While these links can connect users to various onion services, it is crucial to understand that the mere presence of a .onion address does not guarantee that the source is legitimate or safe. Attackers can easily create rogue onion addresses that impersonate genuine services, thus posing a risk to users who may inadvertently disclose sensitive information[9].
The risks associated with accessing these environments are substantial. Users may encounter scams, malware, and illegal content, as well as fabricated datasets. For instance, some sites may offer what appears to be legitimate combo lists but are actually designed to harvest users' credentials through phishing techniques. Additionally, infostealer logs can capture sensitive information directly from infected devices, making them a severe threat to users' security[8].
Credential stuffing remains a prevalent tactic among cybercriminals, exploiting username-password pairs from combo lists to attempt logins across numerous unrelated services. This method can lead to account takeovers, especially if users have a habit of reusing passwords[2]. To protect against these threats, individuals should adopt unique passwords for different accounts and enable multi-factor authentication wherever possible[3]. Regular checks for potential exposure through services like Have I Been Pwned can also assist users in maintaining their security without needing to engage directly with compromised data[4].
Security Implications: Credential Stuffing and Account Takeover
Password reuse significantly increases the risk of credential stuffing, where automated tools test username-password pairs against multiple services. When users employ the same credentials across different platforms, a breach from one site can lead to unauthorized access on others. This situation often results in account takeover, phishing, impersonation, or recovery-email abuse. It's critical to distinguish between exposure—where credentials have been compromised—and confirmed unauthorized access, which indicates that an attacker successfully logged into an account using those credentials.
To evaluate the risk of credential stuffing and account takeover, we can use a simple risk matrix that considers several factors: password reuse, account importance, multi-factor authentication (MFA) status, and evidence of a successful login. For instance, an account with sensitive information, such as banking details, that uses a reused password and lacks MFA is at a high risk. Conversely, an account with unique credentials and MFA enabled is significantly more secure.
Risk Matrix
| Factor | High Risk | Medium Risk | Low Risk |
|---|---|---|---|
| Password Reuse | Reused across multiple important accounts | Reused on less critical accounts | Unique for each account |
| Account Importance | Sensitive information (banking, email) | Moderate value (social media) | Low value (forums, newsletters) |
| MFA Status | No MFA enabled | MFA enabled but with recovery options | MFA enabled with strong authentication |
| Evidence of Successful Login | Confirmed unauthorized access | Suspicious login attempts | No suspicious activity detected |
This matrix helps users identify where to focus their security efforts. For example, if an account has confirmed unauthorized access and uses a reused password without MFA, immediate action is necessary to secure that account. Regular monitoring for potential exposure through services like Have I Been Pwned is advisable, especially after receiving alerts related to combo lists[4].
In summary, understanding the implications of credential stuffing and the associated risks is essential for all users. Implementing unique passwords, enabling MFA, and promptly responding to alerts can significantly mitigate the risk of account takeover and enhance overall security.
How to Check Whether Your Credentials Were Exposed
To determine if your credentials have been exposed, several legitimate resources can assist you. One widely recognised option is Have I Been Pwned, which allows users to check their email addresses against known data breaches. This service can also check passwords through its Pwned Passwords feature, although it does not return the specific password associated with a user, ensuring privacy and security[4].
Google has integrated dark-web monitoring features that alert users if their information is found in compromised databases, enhancing user awareness of potential threats. These alerts can prompt immediate action, such as changing passwords or enabling multi-factor authentication[3].
Established identity-monitoring services offer comprehensive monitoring of personal information across multiple platforms, alerting users to any suspicious activity or exposure. However, these services may not always guarantee immediate detection of all breaches, so it is prudent to use multiple resources for effective monitoring.
When using any lookup tool, it is essential to avoid entering passwords directly. Instead, utilise services that allow for secure checks without disclosing sensitive information. For example, Pwned Passwords supports privacy-preserving checks by sending only a hash of the password instead of the plaintext[4].
To ensure the legitimacy of the resources you choose, follow this source-verification checklist:
- Ownership: Confirm that the service is operated by a reputable organisation.
- Privacy Policy: Review the privacy policy to understand how your data will be handled.
- HTTPS: Ensure the website uses HTTPS to encrypt data in transit.
- Independent Reputation: Look for reviews or reports from independent cybersecurity sources.
- Data-Handling Claims: Verify any claims regarding data handling and security practices.
By employing these defensive resources and following the checklist, you can take actionable steps to protect your credentials and mitigate the risks associated with potential exposure.
What to Do After a Combo List Notification
Receiving a notification about a combo list alert requires immediate action to protect your online accounts. Follow this prioritized checklist to mitigate potential risks:
Change the Affected Password: Start by changing the password on the affected account through the official website. Ensure that the new password is strong and unique to prevent future breaches. This step is crucial as it directly addresses the compromised credentials.
Replace Reused Passwords Elsewhere: If the compromised password has been reused on other accounts, it is vital to change those passwords as well. Password reuse significantly increases the risk of credential stuffing, where attackers use the same credentials across multiple services[2].
Enable Multi-Factor Authentication (MFA): Implement MFA on all accounts that offer this feature. MFA adds an extra layer of security, making it much harder for attackers to gain access, even if they have your password[3].
Review Sessions and Recovery Settings: Check the active sessions on your accounts and terminate any that seem suspicious. Additionally, review your recovery options to ensure they are secure and up-to-date. This includes verifying that recovery emails or phone numbers are still accessible to you.
Monitor Financial or Email Accounts: Keep a close eye on your financial accounts and email for any unusual activity. This includes monitoring bank statements and email alerts for unauthorized transactions or logins. The FBI reported significant losses from bank-account takeovers, emphasising the need for vigilance[6].
In certain situations, it may be necessary to contact service providers, banks, or employers. If you notice any suspicious activity or if your accounts have been compromised, reach out to them immediately. Additionally, if you suspect identity theft, contacting identity-theft authorities can help you navigate the recovery process.
It is essential to avoid contacting sellers or attempting to download the combo list to verify an alert. Engaging with those who trade in stolen credentials can expose you to further risks and potentially illegal activities. Instead, focus on securing your accounts and monitoring for any signs of unauthorized access. Taking these steps can significantly enhance your security posture and reduce the likelihood of account takeover.
Common Mistakes and Misconceptions
Assuming an alert proves the named website was breached
A combo-list match may involve credentials stolen from another service and tested against the named website through credential stuffing[2]. We recommend checking the provider’s security notices and your account activity separately rather than describing the alert as a confirmed breach.
Calling every credential dump a combo list
A conventional combo list contains username-password pairs for automated login testing, whereas infostealer output may also contain cookies, session tokens, financial data, and device context[1][8]. We should classify the material by its reported contents and collection method because an endpoint infection requires different investigation from password reuse.
Treating size or formatting as proof of authenticity
Large record counts and orderly columns can make a claim appear credible, but neither establishes provenance, freshness, or accuracy. Combo-list formatting can use different delimiters and appear as text, SQL statements, or compressed archives, so presentation alone cannot validate the data[5].
Using dark-web posts as a verified incident record
A seller’s description, screenshot, or forum post is a claim, not a source-verified incident report. We advise looking for an attributable provider disclosure, court filing, regulator notice, or recognised breach record without downloading samples or testing the advertised credentials.
Treating a negative breach lookup as an all-clear
Have I Been Pwned checks an email address against known breaches and does not return the password associated with that user[4]. A negative result only means the searched identifier was not found in that service’s available records; we should still investigate unexpected login alerts, password reuse, and account changes.
Assuming MFA makes an exposed password harmless
MFA reduces reliance on a password alone, but it does not make continued use of an exposed password appropriate. After an exposure notification, the correct response is to replace that password anywhere the same or a similar value was used, then enable MFA[3].
Before you go
What is a dark web combo list?
What is the difference between a combo list and an infostealer log?
A combo list normally organises username-password pairs for automated testing, while an infostealer log may contain browser passwords, cookies, session tokens, financial information, and device context taken from an infected endpoint[8]. If an alert identifies infostealer data, we advise scanning the device, revoking active sessions, and replacing exposed credentials rather than treating it only as password reuse.
Are onion links that claim to host combo lists safe?
No: a .onion address only identifies a service available through Tor and does not prove who operates it or whether its files are safe. Attackers can create rogue onion addresses that impersonate legitimate services[9]. We advise verifying an alert through the affected provider or a recognised breach-checking service instead of opening, downloading, or searching stolen credential files.
Can dark web monitoring remove my information from a combo list?
No. Monitoring can report a detected exposure, but it does not give the provider control over downloaded files, private channels, or redistributed copies. We should treat removal claims cautiously and focus on making the exposed data unusable by changing affected passwords, replacing reused variants, revoking sessions, and enabling multi-factor authentication.
Conclusions
- A combo-list warning indicates possible credential misuse, not conclusive evidence that the named platform suffered a breach.
- We recommend securing the referenced account first, then finding every service where the same password or a variation appears.
- Use official account controls and reputable breach-checking services; never inspect leaked files, contact sellers, or test exposed logins.
- Review recent sign-ins, recovery details, forwarding rules, and active sessions, then report unexplained financial or workplace activity to the relevant organisation.
- Treat monitoring as an early-warning measure rather than proof of safety, because coverage depends on the records available to each service.
Next, read Dark Web Hacking to distinguish credential stuffing from other attack methods and choose the appropriate defensive response.
Where this comes from
- United States v. Austad and Stokes — Criminal Complaint
- Credential Stuffing Prevention Cheat Sheet
- Have You Been Affected by a Data Breach? Read On
- Have I Been Pwned API Documentation
- The 773 Million Record "Collection #1" Data Breach
- Justice Department Announces Seizure of Stolen-Password Database Used in Bank Account Takeover Fraud
- End of the Game for Cybercrime Infrastructure: 1025 Servers Taken Down
- Microsoft Digital Defense Report 2025
- Onionspray Security Model
Dark Websites URLDiscover legitimate dark websites URLs and learn how to access them safely while maintaining your privacy online.
Darkweb Com WebsiteDiscover the Darkweb.com website, your gateway to understanding dark web resources and accessing onion links safely.
Dark Web Browsers ListDiscover the best dark web browsers to access .onion sites securely and privately. Enhance your anonymity with our curated list.