Combolists used to be recycled passwords from old breaches. Not anymore.
SpyCloud research found that 51% of credentials within combolists now overlap with infostealer logs, so the credentials inside are often freshly stolen and still working, posted to Telegram within hours of infection.
Size is not the signal, contents are. SpyCloud analyzes every recaptured combolist to see exactly what it exposes, matches it against your domains to find affected employees, and automates the reset before those credentials get used.