[ THREAT ARCHIVE :: 2021 ]
EXPOSURE SCALE: 3,270,000,000+ RECORDS
COMB (Compilation of Many Breaches) — What Was Leaked & How to Check If You're In It
In February 2021, an interactive indexed database labeled COMB containing 3.27 billion unique pairs of cleartext credentials was published, aggregating data from Netflix, LinkedIn, Exploit.in, and thousands of historical breaches.
INCIDENT YEAR: 2021
ATTACK VECTOR: Mass Aggregate Combolist Sorting & Scripting
SEVERITY RATING: CRITICAL
> COMPROMISED DATA ATTRIBUTES IN THIS BREACH:
[✓] Plaintext Passwords
[✓] Email Addresses
[✓] Cracked MD5/SHA-1 Hashes
[✓] Username Pairings
> TECHNICAL POST-MORTEM & VECTOR ANALYSIS
- COMB is structured as a hierarchical fast-query bash/grep script corpus containing 19 billion lines of de-duplicated plaintext combinations.
- It represents the standard reference library utilized by automated credential-stuffing botnets across SSH, SMTP, and Web logins.
> VERIFY IF YOUR CREDENTIALS APPEARED IN THIS DUMP
Query the DARKLEDGER multi-source engine to check if your email, username, or phone number was indexed in the COMB (Compilation of Many Breaches) dataset.
> STEP-BY-STEP REMEDIATION PLAYBOOK
- Scan your email against the COMB index via DARKLEDGER.
- Audit all passwords matching historical patterns.
- Enforce unique 16+ character passwords generated by open-source password managers.
> FREQUENTLY ASKED QUESTIONS ABOUT THIS BREACH
Q: What does COMB stand for?
COMB stands for Compilation of Many Breaches. It is not a single company hack, but an aggregate encyclopedia of billions of previously stolen credentials.