9049 UHQ Hotmails Leak: 8,984 Webmail Accounts Exposed
In June 2026, HEROIC analysts found a stealer log named "9049 UHQ Hotmails" uploaded to a Telegram channel by a user specializing in webmail credentials. Despite the "9049" label, the verified file contained 8,984 records, each pairing a login URL, an email address, and a plaintext password tied to Hotmail accounts.
Why Webmail Accounts Are a Favorite Target
Criminals who deal in stealer logs often specialize by industry, and webmail is one of the most valuable categories because an email inbox typically controls access to everything else a person owns online. This log's focus on Hotmail accounts, marked "UHQ" for ultra high quality, signals the seller has confirmed these logins still work.
What Was Exposed
- Email Addresses
- Plaintext Passwords
- Associated Login URLs
Why This Matters
Because an email account is the gateway to password resets for banking, shopping, and social media, criminals who buy this log can chain their way from one Hotmail inbox into a victim's other accounts, leading to credential stuffing, account takeover, and financial fraud across the 8,984 people represented here.
How Stealer Logs Work
Stealer logs are created by malware that infects a device and copies saved credentials before sending them to an attacker. Sellers who specialize in webmail, as with this Hotmail focused file, filter and verify the logins before listing them, which makes "UHQ" tagged logs more expensive and dangerous than unverified dumps.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including verified webmail stealer logs like this one. Run a free scan to see if your Hotmail account was among the 8,984 records exposed.
Breach Breakdown
8,984 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds