HEROIC Analysts Spot 2,401 Plaintext Logins in Hotmail 4 File
HEROIC analysts discovered a combolist file named Hotmail 4 circulating on Telegram on January 13, 2026, containing 2,401 records of email addresses, plaintext passwords, and the URLs they unlock. Every pair in the file was stored as readable text, so anyone who grabs it can start using the logins right away. The only way to know for certain whether your information is part of this file is to scan your email.
The Real Risk Behind Plaintext Passwords
Because every password in Hotmail 4 was saved in plain, readable text, no cracking or guessing is required: anyone holding the file can plug a listed email and password straight into a login screen. The URLs bundled with each pair point attackers to exactly which site each login opens, saving them the trouble of guessing where else to try. Since most people reuse the same password across several accounts, a single leaked pair can unlock email, shopping, or financial logins far beyond the original file.
What Hotmail 4 Actually Contains
- Email Addresses: identifies who owns each account and lets attackers target that person directly with phishing.
- Plaintext Password: readable immediately, so it can be used to log in without any cracking.
- URLs: tells attackers exactly which site or service each credential pair unlocks.
What This Could Cost the People Affected
Anyone whose email and password appear in Hotmail 4 faces an immediate risk of account takeover on the site the matching URL points to. If that account is an email inbox, an attacker can use it to request password resets on banking, shopping, or social accounts tied to that address, turning one leaked pair into several compromised accounts. Because this file has already been verified, these are not theoretical risks; the credentials work the moment someone tries them.
How a Combolist File Like This Comes Together
A combolist is not a break in at one company's servers. It is a compiled list of email and password pairs gathered from smaller leaks and infected devices, then bundled and shared by whoever assembles the file. According to HEROIC analysts, files like this one are often tested against live login pages before being posted, which is why matching URLs are included. The word "Hotmail" in the file name simply describes the kind of email addresses inside, not that Hotmail's own systems were broken into.
Could Your Hotmail Address Be in This File?
The fastest way to find out is to scan your email against Hotmail 4 and the other files HEROIC tracks; results come back in seconds. If you get a match, change the password on that account immediately and update it anywhere else you used the same one. Check both your personal inbox and your work email, since files like this rarely separate the two.
Breach Breakdown
2,401 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds