Live Threat Pulse: 2,847 threats detected in last 24h

menu_book Data Type

Combolist

Also known as: Combo list, Combo

A combolist is a compiled list of username/email and password combinations, aggregated from breaches and stealer logs, used to fuel credential-stuffing and account-takeover attacks. Combolists are traded widely and are a core commodity of the credential-theft economy.

What is a combolist?

A combolist (combination list) is a plaintext file of credential pairs — typically email:password or username:password — assembled from multiple sources including data breaches, phishing, and infostealer logs. They are shared and sold on forums and Telegram, often for little or no cost.

How combolists are used

Attackers feed combolists into credential-stuffing tools that test the pairs against many sites at scale. Because of password reuse, even a low success rate yields working accounts. Combolists derived from fresh stealer logs are more dangerous than old breach data because the credentials are more likely to still be valid.

How VantaPrism Tracks Combolist

VantaPrism focuses on the upstream source — fresh infostealer logs — so organisations can reset exposed credentials before they are aggregated into the combolists that drive credential-stuffing campaigns.

Check Your Exposure arrow_forward

Frequently Asked Questions

Where do combolists come from?

expand_more
They are aggregated from data breaches, phishing, and infostealer logs, then compiled into plaintext credential lists traded on forums and Telegram.
← All Glossary Terms Last reviewed: June 2026