Analysts Link X2222 Hotmail Dump to 2,210 Exposed Credentials
What HEROIC Analysts Found in the X2222 Hotmail Combolist
In July 2026, HEROIC analysts identified a combolist named "X2222 HQ H0TMAIL," uploaded to a Telegram channel by an anonymous user. The file contained 2,210 records of email addresses paired with plaintext passwords and the URLs those credentials were used on, with a focus on Hotmail accounts.
Why This Is Dangerous
The "HQ" label in the file's name signals the compiler's claim that these credentials are high quality and likely still active. Combined with plaintext passwords tied directly to Hotmail addresses, an attacker has what they need to attempt logins immediately, and potentially reach any other account linked through that inbox.
What Was Exposed in the X2222 Hotmail Combolist
- Email addresses (Hotmail-focused)
- Plaintext passwords
- URLs of the associated websites
Why This Matters for the 2,210 Affected Accounts
Hotmail inboxes are commonly used to receive password reset links for other services. Anyone among the 2,210 affected accounts who reused their password elsewhere, or who relies on that inbox for account recovery, faces a heightened risk of account takeover, identity theft, or financial fraud.
How a Combolist Like X2222 Gets Built
Lists like this one are compiled from older breaches and stealer malware logs, filtered by email domain to target Hotmail users specifically, then labeled and shared through Telegram channels for sale or free distribution.
Check If You Are Affected
If you use Hotmail or any other email provider, HEROIC's free breach scanner checks your address against more than 400 billion leaked records, including combolists like this one. Run a scan now to see your exposure and secure your accounts.
Breach Breakdown
2,210 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds