Hotmail Combo2 Dump: 7,431 Stolen Login Credentials Exposed
On October 8, 2024, HEROIC analysts identified a combolist named "HOTMAIL COMBO2" uploaded to Telegram. The file contains 7,431 records, each pairing an email address with a plaintext password and the URL the login was used on.
Why the Hotmail Combo2 Leak Is Dangerous
Every password in this file is stored as plain, readable text. That means an attacker can use the credentials immediately, without cracking or decoding anything, to attempt logins on Hotmail, Outlook, and any other site where the same password may have been reused.
What Was Exposed in Hotmail Combo2
- Email addresses
- Plaintext passwords
- URLs linked to each set of credentials
Why This Matters
Email accounts are often used to reset passwords on banking, shopping, and social media sites. If your Hotmail login appears in this file and you reused that password anywhere, an attacker could use it as a stepping stone into other accounts, leading to financial fraud or identity theft.
How a Combolist Like This Is Put Together
Combolists such as Hotmail Combo2 are typically built by combining stolen credentials from stealer logs, phishing campaigns, and previous breaches into a single file. These lists circulate on Telegram and dark web forums, where criminals use them to run automated credential stuffing attacks.
Check If You Are Affected
HEROIC's free breach scanner checks your email against more than 400 billion leaked records, including this combolist. Run a free scan today, and change any reused passwords if your information turns up.
Breach Breakdown
7,431 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds