Account Takeover Risk Rises After 7.5K Hotmail Leak of 5,065 Logins
What HEROIC Analysts Found in the 7.5K Hotmail Leak
In November 2025, HEROIC analysts identified a combolist titled "7.5K Hotmail," uploaded to a Telegram channel by an anonymous user. The file contained 5,065 records of email addresses paired with plaintext passwords and the URLs those credentials were used on, with a focus on Hotmail accounts.
Why This Is Dangerous
Hotmail addresses are frequently used as the recovery contact for other online accounts. A plaintext password matched directly to a Hotmail login gives an attacker a way into that inbox, and from there, a potential path to reset passwords on other services tied to it.
What Was Exposed in the 7.5K Hotmail Combolist
- Email addresses (Hotmail-focused)
- Plaintext passwords
- URLs of the associated websites
Why This Matters for the 5,065 Affected Accounts
With over five thousand credential pairs in the file, attackers can automate login attempts at scale. Anyone among the 5,065 affected accounts who reused their Hotmail password elsewhere faces real risk of account takeover, identity theft, or financial fraud.
How a Hotmail-Focused Combolist Gets Built
Compilers sort stolen credentials by email domain, in this case Hotmail, because narrowing the target list makes automated credential stuffing faster and more effective. The resulting file is then packaged and shared through Telegram, as this one was.
Check If You Are Affected
If you use Hotmail or any other email service, HEROIC's free breach scanner checks your address against more than 400 billion leaked records, including combolists like this one. Run a scan now to see your exposure and secure your accounts.
Breach Breakdown
5,065 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds