The et0kenneth Hotmail Breach Happened in January 2025. 534 Logins Still Circulate.
HEROIC analysts identified a second stealer log batch uploaded by Telegram user et0kenneth in January 2025, containing 534 verified valid Hotmail account credentials. Like the companion batch uploaded the same day, this file exposes email addresses, plaintext passwords, and URLs of targeted services. The credentials were verified as active logins at the time of distribution, meaning these Hotmail accounts were accessible to anyone who obtained the file -- and they may have remained unchanged and vulnerable long after the initial upload.
Why a January 2025 Hotmail Dump Is Still a Threat Today
Stealer log data does not expire when the file is first uploaded. These 534 verified Hotmail credentials were distributed in January 2025, and unless each of those account holders changed their password after a breach notification -- which many never receive -- those same credentials may still work today. Attackers do not use all stolen credentials immediately. They store, trade, and revisit credential dumps months or years later. A password that was valid in January 2025 and never changed is just as exploitable now.
Data Exposed in This et0kenneth Hotmail Valid Batch
- Email Addresses -- 534 Hotmail and Outlook account addresses verified as active Microsoft identities
- Plaintext Passwords -- Confirmed-working passwords harvested from browser credential stores on infected devices
- URLs -- The specific Microsoft login pages and linked services each credential pair targets, giving attackers a precise attack roadmap
What Attackers Can Do With These Verified Hotmail Credentials
- Credential stuffing -- The 534 verified passwords are immediately tested across all major platforms where the victim may have reused the same pasword
- Account takeover -- Confirmed inbox access lets attackers reset passwords for banking, shopping, and social media accounts linked to the Hotmail address
- Identity theft -- Years of personal email correspondence, tax records, and scanned identification documents stored in Hotmail give attackers everything needed for fraud
- Financial fraud -- Inbox access enables attackers to intercept payment notifications, redirect transfers, and exploit Microsoft-linked payment methods
The et0kenneth Breach Happened in January 2025 -- The Data Is Still Circulating
When threat actor et0kenneth uploaded this file of 534 verified Hotmail credentials to Telegram in January 2025, it entered a permanent distribution ecosystem. Telegram channels share and re-share credential files for months. Underground marketplaces sell access to archived dumps indefinitely. A file uploaded in January 2025 can still be downloaded and actively exploited in 2026 or beyond. This is why breach monitoring is an ongoing necessity rather than a one-time check. The harvesting happened before January 2025 -- likely weeks or months earlier, when the stealer malware infected victims' devices and silently collected their browser-saved credentials. The upload date marks when the data became widely accessible, not when the compromise first occurred. HEROIC tracks when these files enter public circulation and adds them to the breach database so users can be notified regardless of how long ago the original infection took place.
This Data Went Public in January 2025 -- Check Now If You Were Affected
HEROIC's free breach scanner checks your email address against this et0kenneth dump and more than 400 billion other compromised records, including files that have been in circulation for years. If your Hotmail appears in this batch, you will be alerted immediately. Check at HEROIC.com now -- it is free, takes under 10 seconds, and may tell you something about your account that you had no way of knowing.
Breach Breakdown
534 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds