615 Hotmail Passwords Just Surfaced in a Telegram Stealer Log
In May 2026, HEROIC analysts found a stealer log simply labeled "HOTMAIL" being shared on Telegram. It contained 615 records, each pairing an email address with a plaintext password and the login URL that password was used on, pulled from infected devices rather than a Microsoft server breach.
Why This Is Dangerous
Each of the 615 records already contains a working email, its plaintext password, and the exact site it unlocks. That means anyone who gets this file can log directly into the accounts it names, without needing to crack or guess anything.
What Was Exposed
- Email addresses tied to Hotmail and related Microsoft accounts
- Plaintext passwords stored without any encryption
- Login URLs showing exactly which sites each password unlocks
Why This Matters
Because email accounts are often used to reset passwords for banking, shopping, and social media, a compromised Hotmail login can open the door to far more than just email. Anyone in this leak who reused a password faces a real risk of credential stuffing and account takeover.
How This Hotmail Stealer Log Was Collected
Stealer malware infects a device, quietly reads the passwords saved in the browser, and sends them back to whoever controls the malware, along with the site each password belongs to. This "HOTMAIL" file appears to be one such batch, shared on Telegram for other criminals to search through.
Check If You Are Affected
If you use a Hotmail or Microsoft account, it's worth checking whether your details turned up in this leak or another one like it. HEROIC's free breach scanner searches more than 400 billion leaked records, so you can find out in seconds and secure your account before anyone else does.
Breach Breakdown
615 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds