Back to Blog

XSS.IS Combolist Exposed 2.47 Billion Credentials: Anatomy of a Mega-Breach

LeakedSource Team
|

When the XSS.IS Combolist surfaced in February 2019, it represented something unprecedented in cybersecurity: a single repository containing 2.47 billion compromised credentials — complete with email addresses, usernames, and plaintext passwords. To put this in perspective, that's roughly one credential for every three people on Earth.

This wasn't a traditional data breach. It was something far more dangerous: a meticulously curated aggregation of credentials harvested from thousands of smaller breaches, compiled into a searchable database and circulated among cybercriminals.

How Combolists Weaponize Old Breaches

The XSS.IS Combolist didn't originate from a single vulnerable server or exploited application. Instead, it represents years of accumulated data from countless sources — forums, gaming sites, e-commerce platforms, and corporate databases — merged into a single, searchable collection.

Cybercriminals create these "combolists" specifically for credential stuffing attacks. Here's how the attack chain works:

  • Attackers obtain the combolist containing billions of email/password pairs
  • Automated bots test these credentials across thousands of websites simultaneously
  • Because you likely reused passwords across multiple services, a breach from an obscure forum in 2015 suddenly grants access to your bank account in 2019
  • Successful logins are sorted, packaged, and resold as "fresh" credentials

The XSS.IS collection proved particularly valuable to attackers because it contained plaintext passwords — not hashed versions requiring cracking. Every credential was immediately usable.

The Scale of Exposure

Among the 23.6 billion records indexed in the LeakedSource database, XSS.IS represents over 10% of all exposed credentials. But size alone doesn't tell the full story.

What makes this breach especially dangerous is its overlap with other major incidents. Analysis shows significant credential reuse across:

  • Collection #1 (649 million records)
  • Exploit.in (503 million records)
  • AntiPublic (348 million records)

If your credentials appeared in any earlier breach, there's a substantial probability they were incorporated into XSS.IS. And if you never changed your password after those earlier incidents, your accounts remained vulnerable for years.

The Plaintext Password Problem

Currently, 1,822 breaches in our database contain plaintext passwords — meaning the sites that were breached stored your password in readable format instead of properly hashing it. The XSS.IS Combolist amplified this problem exponentially.

When a site stores passwords in plaintext, a single breach doesn't just compromise that one account. It compromises every account where you used that password. Cybercriminals know this. That's precisely why combolists are so valuable on underground markets.

Consider this scenario: You registered for a small photography forum in 2016 using your primary email and a password you also use for banking. That forum suffered a breach, stored passwords in plaintext, and your credentials ended up in XSS.IS three years later. Attackers now have a direct path to your financial accounts.

Protecting Yourself After Mega-Breaches

The XSS.IS Combolist and similar aggregations fundamentally changed the threat landscape. Traditional advice about changing passwords after breaches is no longer sufficient when billions of credentials circulate indefinitely.

Immediate actions you should take:

  • Check your exposure — Determine if your email addresses appear in the XSS.IS Combolist or other major breaches
  • Enable unique passwords everywhere — Password managers make this manageable; there's no excuse for reuse
  • Activate multi-factor authentication — Even if attackers have your password, MFA blocks most credential stuffing attempts
  • Monitor for unauthorized access — Regular security checkups catch compromises before damage occurs

The breach happened years ago, but the data remains in circulation. Cybercriminals don't delete old combolists when new ones emerge — they layer them, creating ever-more-comprehensive attack databases.

The Data Doesn't Disappear

Here's the uncomfortable truth: the 2.47 billion credentials from XSS.IS still exist on underground forums and marketplaces. They're being traded, sold, and used for attacks right now. The breach date of February 2019 marks when the collection became public knowledge, not when the danger ended.

Our analysis of breach type distribution reveals that 17,475 stealer logs now contribute to the credential ecosystem alongside traditional database breaches. These malware-harvested credentials get fed into new combolists, creating an endless cycle of exposure.

Every day, automated bots attempt billions of login combinations across the internet. A significant percentage of those attempts use credentials from XSS.IS and similar collections. If you haven't changed passwords since 2019, you're leaving those accounts vulnerable.

Know Your Risk

The XSS.IS Combolist demonstrates why breach monitoring isn't optional anymore. With over 23,000 distinct breaches tracked and new credentials added daily, no one can reasonably track their exposure manually.

Find out if your credentials appear in the XSS.IS Combolist, Collection #1, or any of the 23,472 breaches in our database. Search your email address at LeakedSource and receive a detailed report showing exactly which breaches exposed your information — and what data types were compromised.

Your credentials are likely already circulating. The question is whether you'll find out before attackers use them.

Check Your Breach Exposure

Find out if your email address has been compromised in any known data breaches.

Scan Your Email Now

LeakedSource Support

AI assistant — a human reviews escalated chats

This chat has been escalated to our support team — a human will reply here or by email. If you haven't shared your email yet, just type it here so we can reach you.
Hi! I'm the LeakedSource assistant. Ask me about scans, breaches, billing, or your account.