2,300 Hotmail Passwords Dumped on Telegram
HEROIC uncovered a stealer log collection targeting Hotmail accounts, labeled 2.038 hotmail, that was uploaded to Telegram in June 2025. The dump contains 2,300 compromised credential records focused specifically on Microsoft Hotmail users, providing attackers with ready-to-use login credentials for one of the world's most widely used email platforms.
Plaintext Hotmail Passwords: An Open Invitation
All 2,300 passwords in this dump are stored in plaintext, captured exactly as victims typed them. For Hotmail credentials specifically, this is particularly dangerous because a Hotmail password often grants access not just to email but to the entire Microsoft account ecosystem, including OneDrive, Skype, Xbox Live, and any services linked through Microsoft sign-in. Attackers need no special tools to use these credentials; they can log in immediately.
What Was Exposed
- Email Addresses — Hotmail accounts that serve as primary login identifiers for Microsoft services and as recovery addresses for third-party platforms
- Plaintext Passwords — Microsoft account credentials in readable form, ready for instant exploitation
- URLs — the Microsoft login pages and related services where credentials were captured
Email Account Compromise Enables Further Attacks
Compromised email accounts are among the most dangerous credential types because they serve as the master key to a victim's digital life. Attackers who access a Hotmail inbox can initiate password resets for banking sites, social media accounts, and cloud services linked to that email address. They can also send phishing messages to the victim's contacts, amplifying the attack from a single compromised credential into a network-wide threat.
Stealer Logs Targeting Specific Email Providers
Unlike general-purpose credential dumps, this collection was specifically curated to target Hotmail users. Infostealer malware captures credentials from infected devices indiscriminately, but threat actors often sort and filter the resulting logs by email provider to create focused collections. These targeted dumps command higher value on underground markets because they allow attackers to concentrate their efforts on a single platform, increasing efficiency and success rates.
Check If Your Credentials Were Exposed
If you have a Hotmail account, your credentials may be in this dump. HEROIC's breach scanner indexes over 400 billion records and can check whether your email or password appeared in this Hotmail-targeted leak or any other known breach. Search now and secure your Microsoft account before unauthorized access occurs.
Breach Breakdown
2,300 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds