Analysts Trace the Hotmail.calogsfox Leak to 88,024 Logins
HEROIC analysts identified a combolist named hotmail.calogsfox, uploaded to Telegram and dated August 28, 2025, containing 88,024 records of email addresses, plaintext passwords, and associated login URLs. The name suggests the list focuses on Hotmail and other webmail accounts, though it was distributed as a generic combolist rather than tied to a single confirmed source. Why This Is Dangerous: Because the passwords are stored in plaintext, an attacker can use them the moment they access the file, no cracking required. With 88,024 credential pairs, automated tools can attempt logins at scale within minutes, and any reused password becomes an open door. What Was Exposed: Email addresses, plaintext passwords, and the URLs each credential was meant to unlock, together forming a working login attempt for every record. Why This Matters: A list this size is large enough to support serious credential-stuffing campaigns against webmail, banking, and shopping accounts. Since webmail addresses are often used to reset passwords elsewhere, a compromised email account can become the key to unlocking someone's entire online identity. How This Combolist Was Built: Combolists like this one are usually stitched together from older breaches and malware-infected devices that harvested saved logins, then organized and shared on Telegram under a descriptive name like hotmail.calogsfox to attract buyers interested in webmail credentials. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including lists like this one. Run a scan now to see if your account is affected and secure any password you've reused.
Breach Breakdown
88,024 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds