10,187 Email Addresses Exposed in the HOTMAIL Stealer Log Leak
HEROIC analysts identified this stealer log on 16-May-2026. The breach exposed 10,187 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as HOTMAIL.
Why This Is Dangerous
Hotmail is one of the most widely used email services in the world, operated by Microsoft. This file contains 10,187 Hotmail email addresses paired with their plaintext passwords. Because Hotmail accounts are often linked to Microsoft services including OneDrive, Xbox, and Microsoft 365, access to a single Hotmail login can give a hacker entry to multiple platforms simultaneously.
What Was Exposed
- Email addresses (Hotmail accounts)
- Plaintext passwords
- URLs (websites where credentials were used)
Why This Matters
A compromised Hotmail account is a skeleton key. Hackers can use inbox access to reset passwords on every connected service, from banking to subscription accounts. With 10,187 affected addresses in this file, criminals have a large set of Microsoft ecosystem entry points to exploit. Victims may not realize their accounts are compromised until money has been moved or personal information has been used for identity theft.
How a Stealer Log Works
Stealer malware captures login credentials from browsers and apps running on infected devices. It records what users type and also extracts passwords saved in browser password managers. Hotmail-targeted files like this one often originate from infected Windows computers where the user was actively using their Hotmail account through a browser or Outlook.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to see if your credentials appear here or elsewhere. Free, takes seconds.
Breach Breakdown
10,187 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds