4.4M Plaintext Passwords Dumped in Hotmail Combolist
HEROIC analysts detected a massive stealer log titled "5M MIX HOTMAIL COMBOLIST" that was uploaded to a Telegram channel on June 27, 2026. The file contained a staggering 4,490,615 records, each linking an email address to a plaintext password and the URL where the credential was captured. At nearly 4.5 million entries, this is one of the largest single stealer log uploads observed in recent months, representing a significant threat to a vast number of individuals.
Why 4.5 Million Plaintext Passwords Demand Immediate Attention
The scale of this leak is difficult to overstate. With 4,490,615 plaintext passwords in circulation, there are no cryptographic protections to slow down attackers. Every single credential pair in this file is immediately usable without any cracking, decryption, or additional processing. An attacker with this file has 4.5 million ready-made login attempts at their disposal.
Plaintext credentials are the most actionable form of stolen data. While hashed passwords might buy victims time as attackers work to reverse them, these passwords offer no such buffer. The moment this file appeared on Telegram, millions of accounts became vulnerable to immediate unauthorized access.
The Hotmail and mixed-provider focus of this combolist means the credentials span a wide range of email services and associated accounts, making this dump useful for attackers targeting virtually any online platform.
What Was Exposed in the 5M Hotmail Combolist
- Email Addresses — Millions of email addresses spanning Hotmail, Outlook, and other providers, each serving as both a login identifier and a direct communication channel that attackers can exploit for phishing.
- Plaintext Passwords — Nearly 4.5 million passwords stored in the clear, ready for immediate use in login attempts across any platform where victims may have reused them.
- URLs — The websites and services where each credential was originally captured, providing attackers with a directory of confirmed targets for each stolen login.
Why a Leak This Large Fuels Attacks Across the Internet
A combolist of 4.5 million credentials is not just a data point. It is ammunition. Credential stuffing operations thrive on volume, and a dataset this large provides enough material to sustain automated attacks against thousands of websites for months. Even a one percent success rate translates to roughly 45,000 compromised accounts.
The economics of credential stuffing favor attackers at this scale. Automated tools can process millions of login attempts per day across multiple platforms simultaneously. Compromised accounts are monetized through direct fraud, resale on underground markets, spam distribution, and identity theft.
For individual victims, the consequences depend on what accounts their reused passwords protect. A compromised email account can cascade into dozens of additional takeovers through password reset mechanisms, while a compromised banking login can result in direct financial loss.
How Stealer Logs Operate at Industrial Scale
The 5M MIX HOTMAIL COMBOLIST represents the aggregated output of infostealer malware campaigns that infected thousands of devices. Each infection extracts saved credentials from browsers, email applications, and other software, then compiles the data into log files that are uploaded to attacker-controlled servers.
These individual logs are often merged into larger compilations, or combolists, that combine credentials from multiple malware campaigns and sources. The resulting files are shared on Telegram channels and underground forums, where they are downloaded by thousands of threat actors who use them for their own attacks.
The industrial nature of this pipeline means that a single combolist can represent the compromised credentials of people across dozens of countries and hundreds of services, all harvested without the victims ever knowing their devices were infected.
Check If Your Credentials Were Exposed
With 4.5 million records in this single dump, the probability of any given individual being affected is meaningful. HEROIC offers a free breach scanner that searches more than 400 billion compromised records to check whether your email address appears in this or any other known data breach.
Enter your email address to find out if your credentials were part of the 5M MIX HOTMAIL COMBOLIST. If they were, change your password on every account where you used the same credentials. Prioritize your email account, financial services, and any platforms with access to sensitive personal data. Enable two-factor authentication on all accounts that support it.
When a leak reaches this scale, assuming you were not affected is not a safe bet. A quick search is the only way to know for certain whether your data is circulating among attackers.
Breach Breakdown
4,490,615 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds