234 US Accounts Exposed in the Hotmail Fresh B4_Jx Combolist
HEROIC analysts identified a second combolist under the name "Hotmail Fresh B4_Jx," this one surfacing on Telegram in May 2026 with 234 records. As with the earlier release under the same name, the file pairs Hotmail email addresses with plaintext passwords and their associated login URLs.
Why This Is Dangerous
Sellers frequently release combolists in batches under the same name, refreshing the file as new credentials are gathered. This 234-record batch functions the same way as any other: each entry is a working Hotmail login an attacker can try without any additional effort.
What Was Exposed
- Hotmail email addresses
- Plaintext passwords
- Associated login URLs
Why This Matters
A compromised Hotmail account is rarely an isolated problem. Because email addresses are used to verify identity and reset passwords across countless other services, someone with access to this batch could pivot from a single Hotmail login into banking, shopping, or social media accounts tied to the same address.
How Combolists Work
Combolists like this one are typically updated and re-released periodically as sellers gather new credentials, which is why the same "Hotmail Fresh B4_Jx" name can appear more than once with a different record count each time. The underlying process stays the same: aggregate stolen logins, filter by email provider, and package for distribution.
Check If You Are Affected
Search your email with HEROIC's free breach scanner, covering more than 400 billion leaked records, to see if your Hotmail account appears in this batch or any other exposure on file.
Breach Breakdown
234 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds