3.6K Hotmail 13.05 Leak Put 3,681 Stolen Email Pairs Online
HEROIC analysts identified this stealer log on May 13, 2026. The breach exposed 3,681 records, with stolen data including email addresses, plaintext passwords, and URLs. The source is identified as 3.6K Hotmail 13.05 uploaded by a Telegram User.
Why This Is Dangerous
This stealer log specifically targets Hotmail accounts, which are Microsoft email accounts also accessible through Outlook. With 3,681 stolen plaintext passwords now in circulation, attackers have a ready-made list of working email credentials. A compromised Hotmail account can expose linked Microsoft services, saved files, contacts, and any account that uses that email address for password recovery.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- URLs
Why This Matters
With 3,681 stolen Hotmail credentials now available on the dark web, victims face account takeover of their Microsoft accounts, unauthorized access to linked services like OneDrive and Teams, identity theft, and financial fraud if payment information is stored in the account. Credential stuffing attacks can extend the damage to any other site where the same password was reused.
How a Stealer Log Works
Stealer malware harvests credentials from browsers and applications installed on an infected device. It targets auto-saved passwords, browser session cookies, and keystrokes entered during logins. The collected data is packaged into files named by volume or email provider and distributed through private Telegram groups where buyers seek validated access to specific platforms like Hotmail and Outlook.
Check If You Are Affected
HEROIC offers a free breach scanner that searches 400 billion records. Search your email address now to see if your credentials appear here or elsewhere. Free, takes seconds.
Breach Breakdown
3,681 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds