Blacksec

Administrator
Staff member
ROOT
VIP
Hey hackers — what is a combo list gets answered by security-vendor glossaries written to sell monitoring products, a support-page explanation from an antivirus company that missed the point, a StackExchange thread, and a "smart highlight search feature" site that IS the thing the term describes. Nobody explains the actual object: what data physically sits inside a combo list, how they're assembled from breaches/stealers/skimmers, how the scene grades and trades them, why they decay the way they do, the famous case that made the term mainstream (the Anti-Public connection), and how the format differs from fullz, dumps, and logs — the taxonomy properly differentiated, not one table buried in a sibling article. Scene knowledge, street voice, the standing rule at the bottom where it's earned.
TL;DR: A combo list (usually "combo") is a bulk list of credential pairs — classically email:password lines, one per row, assembled at scale from breaches, infostealer logs, skimmers, and aggregation/reselling. It's the WHOLESALE unit of the credential-data world: high volume, per-line value low, quality defined by freshness and match-rate rather than any single line's importance. Distinguished from fullz (structured identity dossiers), dumps (card track data), and logs (raw stealer archives) — the taxonomy table below settles it permanently. And the rules: combo lists rot by design (rotation, 2FA, age), the market around them is adversarial end-to-end, and per this site's standing policy — never purchase CC or credential data from anyone.

What Is a Combo List? (The Precise Definition)​

Formal definition: a combo list is an aggregated file of authentication credential pairs where each line binds an identifier to a secret — overwhelmingly identifier:secret format. The canonical pairing is email:password, but the format family includes username:password, phone:password, email:password:additional_field, and source-annotated variants like site|email|password where every line is tagged with where it came from.
The word doing the work is "list": unlike a fullz record (one person, many fields — structured dossier), a combo line is minimal (one credential pair, no identity scaffold) and a combo LIST is measured in thousands-to-hundreds-of-millions of lines. Individual lines carry almost no value; the artifact's worth is aggregate — bulk validation against login surfaces is the entire economic thesis of the format. That's why the scene treats combos like a commodity grade (freshness, valid-rate, dedup-quality) instead of curated intelligence: wholesale credentials, priced by the ton.
Why the term shows up everywhere in security research:
combo lists are the raw input for credential-stuffing operations (the industry that tests leaked pairs across services at scale), the most-visible output class of infostealer malware, and the payload behind every "credentials exposed" breach headline. Security vendors write about them because they're the dominant bulk-threat artifact — which also explains why vendor glossaries own this query's SERP: the term crossed from scene-vocabulary into threat-intel-vocabulary, and only one side of that crossover writes in street voice.

What's Actually Inside a Combo (Format Anatomy)​

Format variantLine structureTypical originScene notes
Classic comboemail:passwordSite breaches, credential aggregationThe default — "combo" alone means this unless qualified
Site-tagged combosite|email|password or email:pass:siteStealer logs (browsers save per-site), structured exportsHigher utility per line — target annotation makes sorting trivial
User:passusername:passwordForums, older breaches, non-email identitiesSame mechanics, identifier isn't an email
Phone combosphone:passwordMobile-app breaches, SIM-linked servicesRegion-scene formats (carrier-prefix reveals geography)
Hash combosemail:md5hash or salted hash formsBreaches where plaintext wasn't stored/recoveredNeed crack pass before use — different value tier entirely
Multi-field combosemail:pass:name:phone (varies)Breaches with profile data joined to credentialsDrifts toward fullz-lite — more identity per line, still list-formatted
The structural read: every variant keeps the same skeleton — identifier colon secret, one line per credential. Everything else (tags, joins, hashes) is annotation on the core pair. Scene terminology follows the format: "combo" = the pair-line format, "combo list" = the bulk artifact, "combining" = the aggregation process that builds one from multiple sources (the same verb the market uses for its biggest trade good).

How Combo Lists Are Made (The Assembly Pipeline)​

Every combo list in circulation came through some version of this pipeline — sources feed processors, processors feed distributors:
  • Source 1 — Data breaches. The historical foundation: database exfiltration from sites that stored credentials (often plaintext or crackable hashes). A single mega-breach generates tens of millions of lines; these form the "aged bulk" layer of the market that resells for years.
  • Source 2 — Infostealer malware. The dominant source of the 2020s. Stealer families (the commodity lineup security telemetry tracks constantly) vacuum browser-saved passwords, autofill profiles, and session tokens from infected machines — output is per-victim folders of site-tagged credentials. Infostealer corpus → parsed → combo lines with FRESH site annotations. This is why "fresh combos" correlate with malware-campaign timelines rather than breach timelines.
  • Source 3 — Skimming operations. Magecart-class form-capture on compromised checkouts: every credential typed into a poisoned form feeds the pool with payment-adjacent captures.
  • Source 4 — Aggregation & reselling. The meta-source: traders merge lists from other traders (the "combining" step), dedup them, and regrade freshness. Many lists sold as "fresh from a new breach" are re-aggregations of older lists with new labels — provenance dies here, which is why scene-grading (below) obsesses over validity-rate testing instead of claimed origin.
The processing steps every list passes through: format normalization (lines → canonical pair form), dedup (same email:pass appearing across five sources collapses to one), garbage filtering (malformed lines, placeholder values), and optionally validity-checking (automated login testing against services — the step that both grades the list and damages the ecosystem it feeds: each validation generates the auth attempts that defenders observe and victims get notified about).

The Combo Economy: Structure, Not Shopping​

The market's structural tiers — analyzed as an economist would (nobody's buying anything here, the point is understanding why listings look the way they do):
TierSource classWhat actually drives its priceStructural flaw
Fresh parseRecent stealer distributionDays-since-extraction + site-tag completenessDetection velocity — every test burns lines
Fresh breachNewly-disclosed database compromiseNotification lag (pre-rotation window)Window closes as victims get notified — measured in weeks
Aged bulkOld breach corpora, re-aggregatedVolume + dedup quality (nothing else survives)Years of rotation already culled the active-use value
"Premium/vip" bundlesClaims layered on any of the aboveMarketing, not measurable attributesGrade-as-story: the premium pays for presentation
Read the flaw column downward: every tier's price driver is inversely related to its verifiability. The freshest claims (highest price) are the least independently checkable; the most checkable property (line count) is the most gameable (dedup inflation). A market where price and provability anti-correlate is a market running on trust in adversarial conditions — which is the exact structure every other guide on this site has dissected under a different product name.

Combo Lists vs Fullz vs Dumps vs Logs (The Permanent Taxonomy)​

ArtifactUnit of dataFormat shapeVolume profileValue thesis
Combo listCredential pairs (email:password)Flat text lines, millions possibleWholesale — bulk validationAggregate match-rate across services
FullzComplete identity dossiersStructured records per personPer-person pricingIdentity impersonation / verification-passing
DumpsCard track data (PAN+track2)Encoded track stringsPer-cardPhysical cloning
Stealer logsRaw machine captures (cookies, autofills, tokens, files)Folder archives per victimPer-victim archivesSession hijack + everything extractable
The relationships (this is where people lose the plot): stealer logs are the RAW HARVEST; combos are one REFINED OUTPUT parsed from them (alongside fullz-assembly and token-extraction); dumps are a separate payment-data class entirely; and the same breach or malware family often feeds multiple artifact types simultaneously. A "combo list" is thus a VIEW over stolen data — the credential-pair projection — which is why the same underlying compromise shows up in research as "breach X exposed 3M accounts" (combo view) and "breach X exposed full identity records" (fullz view) without contradiction: different extractions of the same source.
Since freshness = everything in this market, the grading vocabulary (read this to understand listings, not to shop — see the standing rule):
"Fresh" vs "aged": fresh = recently extracted (stealer-dated or breach-dated within days/weeks); aged = old breach corpora resold repeatedly. Fresh commands premium because credential rotation hasn't reached the corpus yet — every week of age, more lines die as victims change passwords (the decay curve in the next section).
Valid-rate testing: the market's quality metric — what percentage of lines still authenticate against some target service. Tested (destructively, generating the detection signals mentioned earlier) or claimed (inflated). A "70% valid" claim on a fresh steal-log parse is plausible; on an aged list it's fantasy.
Dedup quality: how aggressively duplicates were stripped across sources. Bad dedup = same dead credential counted five times, inflating line counts (that "400M line" headline number is usually dedup-poor).
Source class: stealer-parsed (site-tagged, fresh) > recent breach (uniform, dated) > old breach (ancient) > re-aggregated claims (provenance dead). The scene prices these tiers differently — and like every grading system in adversarial markets, the grader benefits from your trusting their grade. Verify with live signals or treat grades as marketing.

Why Combo Lists Rot (The Decay Mechanics)​

Combo lists are perishable goods — the shelf-life math is why the market churns:
  • Password rotation. Breach notifications, forced resets, and organic changes kill lines continuously. Industry breach-response data consistently shows large fractions of exposed credentials rotated within weeks of notification — every rotation is a line dying.
  • 2FA on the target side. Even a valid pair can't authenticate where the service requires a second factor — the line isn't "dead" (credentials still correct) but it's dead FOR the use-case the market cares about. Services adopting passkeys/2FA progressively shrink combo utility across the ecosystem.
  • Account lifecycle. Dormant accounts get closed, emails get abandoned, services shut down. A 2019 combo's 2026 value reflects six years of attrition.
  • Detection acceleration. Validated lines trigger lockouts, breach-flagging, and notification cascades — the very act of testing the market's product destroys part of it (the same self-defeating validation loop documented in the carding-economy guides on this site).
The honest half-life estimate the scene won't print: individual lines decay on a curve measured in weeks-to-months post-collection for active-use value; the LIST survives longer only as re-aggregatable raw material. Which explains the market's actual structure — nobody "owns" combos, they hold rotating inventory of partially-decaying lines, forever one stealer-distribution away from restocking. Or, as the standing rule puts it: the only winning position in perishable stolen goods is not inventory.
The combo lifecycle is a leaky bucket described in the language of inventory: harvest faster than rotation, test faster than detection, resell faster than decay. Every participant is racing clocks they didn't start — and the only party consistently winning the race is the one selling buckets to everyone else.

The Anti-Public Connection (How The Term Went Mainstream)​

The phrase "anti public combo list" still gets searched (Ahrefs: live suggestions on this seed) because of the incident that made combo lists a household term in security: the "Anti-Public" aggregation — a merged credential collection whose exposure (documented publicly via Have I Been Pwned's database entry, which ranks for this query even years later) combined multiple breach corpora including well-known sources. The lessons that generalized from it, still true:
  • Aggregation multiplies exposure. The Anti-Public corpus wasn't one breach — it was several, merged. Your credentials may be in a combo list without any single breach "having" everything, because the COMBINING step joins partial exposures into complete ones.
  • "Public" meant free. The list circulated at zero cost — which reframes the market: much of the combo economy's floor is free-floating material, and everything sold above it is either freshness-premium or convenience-premium over material that leaked publicly anyway.
  • Notification infrastructure scaled on incidents like it. HIBP's ingestion of it (and the flood of Have-I-Been-Pwned searches that followed) is why breach-notification literacy exists at consumer scale today. The incident is a case study in how one aggregation shapes an entire ecosystem's response tools.

FAQ​

What is a combo list?​

A bulk list of credential pairs in email:password (or variant) line format, aggregated from breaches, infostealer logs, skimmers, and resellers. The wholesale unit of credential data: individual lines carry minimal value, the artifact's worth is aggregate match-rate. Distinguished from fullz (identity dossiers), dumps (card track data), and stealer logs (raw machine captures) — see the taxonomy table.

Where do combo lists come from?​

Four sources dominate: database breaches (the historical foundation, aged bulk), infostealer malware (the dominant 2020s source — site-tagged fresh parses from infected machines), checkout skimming (form-capture), and aggregation/reselling (merging other lists — where provenance dies and freshness claims get manufactured). The assembly pipeline (normalize → dedup → filter → optionally validate) runs on all of them before distribution.

What is email:password combo specifically?​

The canonical combo line format: an email address, colon separator, the password associated with that email — usually at the same service, one line per credential. It's the default meaning of "combo" unqualified. Source-annotated variants (site tags, extra fields) and hash-form variants (email:hashed-password) exist but the pair skeleton holds across all of them.

Are combo lists still useful in 2026?​

Depends entirely on freshness and the target's authentication posture — the honest mechanical answer: credential rotation has killed large fractions of any aged list, 2FA/passkey adoption shrinks the surface where valid pairs authenticate at all, and modern breach detection notifies faster than old corpora age. Fresh stealer-parsed material retains short-term utility (which is exactly why the freshest source is malware; see the source pipeline), while the "old breach combo" layer is mostly raw material for research rather than anything actionable. The decay section covers the full curve.

Is it illegal to have a combo list?​

Depends entirely on jurisdiction, acquisition, and use — but the honest structural answer: possession of bulk stolen credentials falls under unauthorized-access, data-protection, and identity-fraud statutes in essentially every legal system that's addressed cybercrime (in the US: CFAA and identity-theft statutes; equivalents worldwide). Research contexts (sanitized/authorized datasets through institutional channels) exist for professionals; having scene-sourced lists on a personal machine does not gain legality through a research label. The standing rule on this site sidesteps the question entirely: never purchase CC or credential data from anyone — free, legal knowledge about the format costs nothing.

Combo list vs wordlist — same thing?​

No — different tools, different lineage. A wordlist is an INPUT to cracking/brute-force (candidate passwords, generated or curated — think dictionary files for offline attacks); a combo list is OUTPUT from credential theft (already-paired live credentials, used for testing pairs that already exist). Related only at the edges: a wordlist might be built FROM passwords observed in combos (frequency analysis), and both are "lists of passwords" to an outsider — but one you generate, the other someone stole.

How do sites detect combo list stuffing?​

The validation/testing flow described in the pipeline generates exactly the signals detection systems watch: distributed login attempts with valid-but-unusual credentials, geographic/device mismatch for known accounts, burst patterns from checking-at-scale, and credential-reuse correlation across services. The detection ecosystem (credential-stuffing defenses, breach-notification automation, dark-web monitoring that alerts victims their pair went live) was largely BUILT around this artifact class — which is why validating a combo produces notifications faster than it produces value.

Where To Go From Here​

You've got the precise definition, format anatomy across six variants, the four-source assembly pipeline, the permanent taxonomy vs fullz/dumps/logs, the scene's grading vocabulary (and why to distrust it), the decay mechanics, and the mainstream-breaking case study. That's the complete object — better than any glossary page ranking for this query, and structurally immune to their sales framing.
The data-taxonomy cluster on this site:
  • What Are Fullz — the sibling pillar: identity dossiers, complete anatomy, the marketplace teardown
  • This page — combo lists: the wholesale credential unit (you are here)
  • Non VBV Meaning + Non VBV Bins — the payment-side vocabulary family
  • Carding Robux — where the seller economy around data gets dissected
BlackSec official channel: t.me/Blacksec_official — drops, tradecraft, community. Only official channel we run; "fresh combo drops" marketed under our name are running the acquisition funnels this page described in section three.
Boards: Bins/CC Freebie (this cluster's home) · Databases/Clouds (breach-data discussions) · Courses (credential-security engineering — understanding the artifact from the defender's build side, which is where the paying careers are).
The standing rule, combination #15: never purchase CC or credential data from anyone. Combos are perishable, the grading is marketing, validation destroys what it measures, and the market's counterparty is adversarial by construction. Learn the format free — it's the most-documented artifact class in security — and let everyone else fund the decay.
— BlackSec crew. Format and pipeline current for 2026 (stealer-dominant sourcing, aggregation economics). The ecosystem rotates: when a new source class reshapes the market, the structure (source → process → grade → decay) outlives any specific family name — reason from the pipeline, not the branding.