233 Accounts Leaked in Fresh Hotmails by MrAwexx Stealer Log
HEROIC analysts identified a dataset labeled "Fresh Hotmails By MrAwexx" after it was uploaded to a Telegram channel and logged into HEROIC's threat intelligence system on January 28, 2026. The file contains 233 records built from Hotmail and Outlook style email accounts, each one paired with a plaintext password and the URL of the site where the credential was captured. It is a small file compared to some of the mega-dumps HEROIC tracks, but every one of the 233 records represents a real account that was compromised by malware running on someone's device.
Why the Fresh Hotmails by MrAwexx Leak Is Dangerous
The passwords in this file were not hashed or encrypted, they were stored in plain, readable text. That means anyone who downloads the list can try logging into the associated Hotmail or Outlook accounts immediately, with no cracking required. The inclusion of the exact login URL for each credential also tells an attacker precisely which site the password unlocks, turning a short list into 233 ready-made keys rather than a pile of guesswork.
What Was Exposed
- Email addresses
- Plaintext passwords
- Login URLs tied to each credential
Why This Matters
Most people reuse the same password, or a close variation of it, across several accounts. If any of the 233 people in this leak reused their Hotmail or Outlook password on a banking site, a shopping account, or a work login, this small file could be the starting point for credential stuffing, account takeover, or broader identity theft that has nothing to do with the original email provider.
How Stealer Logs Work
This leak falls into the category HEROIC classifies as a "stealer log." Stealer logs are not the product of a company being hacked, they come from malware, often hidden inside pirated software, a cracked game, or a fake update, that installs itself on a victim's own computer. Once running, it quietly copies saved browser passwords, autofill entries, and site URLs, then bundles everything into a log file and sends it back to whoever controls the malware. That person, in this case operating under the handle "MrAwexx," then shares or resells the log through channels like Telegram. Because the data comes directly off an infected device, stealer logs tend to be fresh and accurate at the moment they're stolen.
Check If You Are Affected
If you use a Hotmail or Outlook address, it's worth finding out whether it appears in this leak or any other exposed dataset. HEROIC's free breach scanner checks your email against a database of more than 400 billion breached records, including stealer logs like this one, so you can see in seconds whether your information has surfaced and take action to secure your accounts.
Breach Breakdown
233 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds