107,609 Hotmail Passwords Were Just Dumped on Telegram
HEROIC's DarkHive threat intelligence platform flagged a massive stealer log dump labeled "110K Hotmail Combo" uploaded to Telegram in November 2024. The file contains 107,609 compromised Hotmail credentials — each record consisting of an email address, a plaintext password, and the associated URL where the login was captured. At over 107,000 entries, this represents one of the larger Hotmail-focused credential dumps detected in recent months.
107,000+ Passwords in the Clear
The scale of this leak is staggering, and the fact that every password is stored in plaintext makes it exponentially worse. More than 107,000 Hotmail passwords require no cracking, no decryption, and no computational effort to exploit. Each one is ready to be used the moment an attacker opens the file. At this volume, automated credential testing tools can process the entire dataset in hours, probing thousands of accounts per minute.
What Was Exposed
- Email Addresses — over 107,000 Hotmail accounts connected to Microsoft's ecosystem
- Plaintext Passwords — stored in fully readable form with zero encryption
- URLs — identifying the services and websites where each credential was harvested
The Massive Scale of Credential Stuffing Risk
With 107,609 email-password combinations, attackers can launch credential stuffing campaigns of enormous scale. They test each pair against major platforms — Microsoft 365, Outlook, OneDrive, Xbox Live, and countless third-party services. Given that industry research shows approximately 65% of people reuse passwords across accounts, this single dump could potentially yield access to hundreds of thousands of additional accounts beyond the original Hotmail logins.
Industrial-Scale Credential Harvesting
A dump of this magnitude points to organized infostealer operations running at industrial scale. Multiple infostealer malware variants — including RedLine, Raccoon, and Lumma — were likely used to collect credentials from infected machines over an extended period. The stolen data was aggregated, filtered for Hotmail addresses, deduplicated, and compiled into this single downloadable file. The organized, systematic nature of the operation demonstrates how professionalized the credential theft ecosystem has become.
Check If Your Credentials Were Exposed
With over 400 billion compromised records indexed in its database, HEROIC provides comprehensive breach detection for individuals and organizations. Use HEROIC's free breach scanner to search for your Hotmail address and determine whether your credentials are included in the 110K Hotmail Combo dump. Given the massive scale of this leak, checking your exposure is an urgent priority for any Hotmail user.
Breach Breakdown
107,609 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds