Account Takeover Risk Rises After the Hotmails 2 Leak of 509 Records
In June 2026, HEROIC analysts found a combolist file named Hotmails 2, posted to Telegram by an individual user. The file contained 509 records of email addresses paired with plaintext passwords and the URLs those logins were tied to. Why is this dangerous? A list this size may look small, but every one of the 509 entries is a working email and password pair stored in plaintext, meaning an attacker can log straight into the account without cracking anything. If any of those 509 people reused their password elsewhere, the risk quickly spreads beyond a single inbox. Here is what was exposed in the Hotmails 2 leak: email addresses, plaintext passwords, and associated URLs. Why this matters: Small combolists are frequently absorbed into larger credential-stuffing toolkits, so even a modest file like Hotmails 2 can end up feeding automated login attempts against dozens of other services. Stolen credentials like these rarely stay in one place. Attackers feed lists like this into automated tools that test each email and password pair against banking sites, email providers, and online retailers, a technique known as credential stuffing. When a password is reused, one exposed account can lead directly to account takeover, identity theft, or financial fraud on completely unrelated services. How the Hotmails 2 Combolist Came Together: A combolist is a curated file of email or username and password pairs, usually pulled from older breaches, phishing campaigns, or malware infections and reorganized into a single list. The Hotmails 2 file appears to be one of these smaller, targeted compilations, built specifically around Hotmail-style email accounts and shared for free on Telegram. Check If You Are One of the 509 Exposed Accounts: You do not have to wait to find out if your information is part of a leak like this one. HEROIC's free breach scanner checks your email address against a database of more than 400 billion exposed records, including combolists and stealer logs like this one, and tells you immediately if your credentials have shown up in a known breach. If you find a match, change that password right away, and avoid reusing it anywhere else.
Breach Breakdown
509 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds