Combo list
Also called: combolist
A combo list is a file of username and password pairs, usually email addresses and passwords, compiled from earlier data breaches, phishing and malware logs. Criminals trade and sell these lists so the pairs can be tried against other services. A combo list is the raw material for credential stuffing and account takeover.
How it works
Sellers merge many breach dumps and stealer logs, remove duplicates and sort the pairs by email domain or target website. Buyers feed the lists into automated login tools. Because many people reuse the same password, even old combo lists still contain pairs that work on other sites.
A real example
In January 2019 Troy Hunt, who runs Have I Been Pwned, described a breach dataset of almost 2.7 billion username and password combinations compiled into lists that could be used for credential stuffing.
Source: The 773 Million Record "Collection #1" Data Breach — Troy Hunt (Have I Been Pwned), 2019-01-16
The Identity Attack Ledger holds 31 cited incidents for phished or stolen credentials in California breach filings (January 1, 2023 – August 14, 2026), each quoted from its filed letter.
How to stop it
Block passwords that already appear in breach corpuses and require MFA, so a pair from a combo list cannot open an account on its own.
Related terms
Sources
- The 773 Million Record "Collection #1" Data Breach — Troy Hunt (Have I Been Pwned), 2019-01-16
Last reviewed Oct 2, 2026