On May 28, 2024, 361.5 million unique email addresses appeared in a massive combolist collection distributed through malicious Telegram channels. The dataset, totaling 122GB across 1,700 files, contains email addresses, usernames, passwords, and in many cases the specific websites where those credentials were used. Anyone whose login details are included now faces immediate risk of account takeover, identity theft, and further doxxing. The breach stems from the aggregation of existing combolists and information stolen by malware, rather than a single hacked company.
Named in this incident?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 582 companies.
See what is exposed about you — free scan →Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.
Primary Disclosure Details
The listing on Have I Been Pwned states that the combolists were collated in May 2024 from malicious Telegram channels. It confirms 361.5 million unique email addresses alongside associated usernames and passwords. The disclosure indicates the data was compiled from multiple prior sources, including longstanding combolists and logs from info-stealer malware. The primary source does not identify any single originating breach or the exact number of individuals whose full records were exposed beyond the unique email count. It also does not specify ransom demands or internal attack details because this is an aggregation of already-circulating stolen data rather than a new intrusion into one organization.
Why This Matters for You and Your Family
When your email, username, and password appear together in a combolist, attackers can automate login attempts across banking, email, shopping, and government portals. Passwords exposed in this collection lose all value if they have been reused anywhere else. Children’s accounts, family shared logins, and older relatives’ email addresses are frequently swept up in these large datasets. Once one account is compromised, attackers pivot to reset linked services, harvest personal documents, or demand payment to stop further leaks. The scale—hundreds of millions of records—means opportunistic criminals will be testing these credentials for months or years.
Doxxing and Identity-Chain Risks
Combolists like this one accelerate doxxing chains because they link usernames, emails, and passwords to specific websites. An attacker who cracks your email can then search for your username on gaming platforms, social media, or forums, mapping your digital footprint back to your real identity, home address, and family members. Credential leaks of this type routinely cascade into full identity theft, SIM-swapping, and extortion. Gaming accounts belonging to you or your children are especially vulnerable because they often reuse the same passwords or recovery emails found in these lists, creating direct pathways to personal photos, chat histories, and location data.