The Good Emails Hotmail Leak: 1,028 Login Credentials Exposed
In October 2025, HEROIC analysts identified a Telegram upload named Good Emails.txt_Hotmail 161, containing 1,028 records of email addresses, plaintext passwords, and the URLs each credential pair was tied to. The file specifically targets Hotmail and Outlook accounts that the uploader had verified as active, or good, logins. Why is this dangerous? Labeling a file good means the uploader has already confirmed these credentials work, unlike raw, unverified combolists. That verification step makes this dataset more immediately dangerous, since an attacker does not need to test which accounts are still valid before attempting to log in. What was exposed: Hotmail and Outlook email addresses, plaintext passwords, and URLs linked to each credential pair. Why this matters: email accounts are often the key to resetting passwords on banking, shopping, and social media sites. A verified Hotmail login gives an attacker a direct path to intercept password reset emails and take over other accounts tied to that inbox, well beyond just reading someone's mail. How this combolist was built: uploaders build verified combolists by running a raw list of stolen credentials through a checker tool that confirms which logins still work, then separating the working good entries from the dead ones before distributing the file. This extra step is why verified lists like this one circulate quickly among criminals looking for ready-to-use accounts. Check if you are affected: if you use a Hotmail or Outlook account, this is worth checking directly. HEROIC's free breach scanner searches your email address against more than 400 billion leaked records, including verified combolists like this one, so you can change your password before someone else logs in first.
Breach Breakdown
1,028 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds