2,247 Passwords Exposed in the HOTMAIL 00002 MOON_SUPP1 Stealer Log
HEROIC analysts identified a stealer log file circulating on Telegram in May 2025, uploaded by a user under the name HOTMAIL 00002 MOON_SUPP1. The file contained 2,247 records pulled directly from infected computers, including email addresses, plaintext passwords, and the URLs of the websites those credentials unlock.
Why This Is Dangerous
Unlike a typical database leak, this data did not come from a hacked company. It came from malware sitting on someone's own computer, quietly recording every username and password typed into a browser. Because the passwords are stored in plaintext and matched directly to the URL they belong to, an attacker does not need to guess or crack anything. They can open the file and log in immediately.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs tied to each login
Why This Matters
Even a small file like this one can cause real damage. If any of these 2,247 people reused a password across other accounts, an attacker can try that same email and password combination on banking sites, social media, and shopping accounts in a technique called credential stuffing. A single reused password can lead to account takeover, financial fraud, or identity theft long after the original malware infection is gone.
How Stealer Logs Work
Stealer log malware infects a device, often through a pirated download, fake software update, or malicious email attachment. Once installed, it quietly reads the saved passwords and autofill data stored in the victim's web browser, then bundles everything into a text file. That file is packaged and sold or shared for free on Telegram channels and dark web forums, exactly as it was in this case. Because the data comes straight from the browser, it is usually accurate and current at the time of infection.
Check If You Are Affected
If you use Hotmail, Outlook, or any of the services tied to this leak, it is worth checking whether your credentials are part of this exposure. HEROIC's free breach scanner searches a database of more than 400 billion leaked records to tell you instantly if your email address has been compromised. Run a free scan and take a few minutes to update any passwords you may have reused.
Breach Breakdown
2,247 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds