Analysts Uncover 1,436 Validated Hotmail Logins in TXTVALID Leak
In April 2026, HEROIC analysts found a combolist titled "Hotmail TXTVALID," uploaded by a Telegram user. The file contains 1,436 records of Hotmail email addresses and plaintext passwords, along with the URLs those credentials were tied to. Why This Is Dangerous: the name TXTVALID indicates the uploader has already validated these credentials as working logins, rather than sharing an unverified list. That verification step makes the file more immediately dangerous, since every record is more likely to grant real access to a Hotmail account. What Was Exposed: Hotmail email addresses, plaintext passwords, and URLs tied to each login. Why This Matters for Hotmail Account Holders: a validated Hotmail login gives an attacker immediate access to an inbox that likely controls password resets for other accounts. From there, credential stuffing and account takeover can spread well beyond the original email account into banking, shopping, and social media logins. How Validated Combolists Like This Get Made: to produce a validated list, sellers typically run automated login checks against real Hotmail servers using credentials pulled from breaches, phishing kits, or stealer malware, keeping only the pairs that successfully authenticate. This process takes more effort than simply dumping raw data, which is why validated lists like this one tend to be considered more valuable and more dangerous. Check If You Are Affected: if you use Hotmail or Outlook, it's worth confirming your account wasn't part of this validated list. HEROIC's free breach scanner searches more than 400 billion leaked records so you can check your exposure and change your password if needed.
Breach Breakdown
1,436 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds