The Hotmail Dump: 1,064 Stolen Login Credentials Hit Telegram in June 2025
HEROIC analysts identified a Hotmail-targeted stealer log file uploaded to Telegram on June 22, 2025 that exposed 1,064 records. The file, distributed by an anonymous Telegram user under the designation "932 hotmail," contained email addresses, plaintext passwords, and endpoint URLs harvested specifically from Microsoft Hotmail and Outlook accounts. This is the second Hotmail-targeted stealer log from the same date, suggesting an operator was actively filtering and packaging platform-specific credentials from a larger raw harvest on that day.
Why Platform-Specific Hotmail Credential Dumps Are Particularly Dangerous
Hotmail and Outlook accounts have been Microsoft's consumer email platform for decades, and many long-term users have never changed their original passwords. This makes Hotmail-specific credential dumps especially effective for attackers: a significant portion of exposed passwords are likely still active. Beyond email access, a compromised Microsoft account unlocks OneDrive, Microsoft 365, Xbox, Bing, and any third-party service that uses Microsoft SSO for sign-in. Attackers who specialise in Microsoft account fraud seek these targeted dumps precisely because the blast radius of a single compromised account extends across the entire Microsoft product ecosystem.
Data Exposed in the 932 Hotmail Telegram Stealer Log
The following data types were confirmed in this stealer log upload:
- Email Addresses (Hotmail and Outlook accounts specifically targeted)
- Plaintext Passwords (unencrypted, no cracking required)
- URLs (specific services the victims were logged into at the time of infection)
What Happens After Stolen Hotmail Credentials Hit Telegram
Once a targeted credential file surfaces in Telegram, the exploitation timeline is fast. Here is the typical attack progression:
- Credential stuffing: Each of the 1,064 email and password pairs is tested against Microsoft login systems and dozens of other platforms that accept Microsoft account credentials, targeting password reuse across services.
- Account takeover: Successful logins result in immediate account lockout of the legitimate owner by adding an attacker-controlled recovery email and phone, making standard recovery imposible without contacting Microsoft support.
- Identity theft: Outlook inbox access reveals bank statement notifications, linked service confirmations, and personal correspondence, providing attackers with a comprehensive picture of the victim's identity for use in fraud applications.
- Financial fraud: Microsoft Wallet, stored payment methods, and Xbox credits are drained immediately, while inbox access to bank notification emails enables targeted phishing of the victim's financial institutions.
What Is a Numbered Hotmail Stealer Log and How Are They Created
Stealer log operators frequently name their files with a number followed by the target platform, such as "932 hotmail." The number typically refers to the original file batch or pack number in the operator's distribution system, not the record count. These files are assembled by filtering raw infostealer harvest data by email domain. When malware like Lumma Stealer, RedLine, or Vidar infects a device and finds saved Hotmail or Outlook credentials in the browser, those entries are harvested alongside all other data. Operators then run domain filters across thousands of raw logs to extract only Microsoft-domain credentials, which they sell or distribute as a premium product. The same-date upload as the earlier "315 hotmail" file suggests both came from the same operator processing a single day's harvest. Together, these two files exposed over 1,400 Hotmail accounts on a singl day in June 2025.
Check If Your Microsoft Account Was Exposed in This Breach
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including Hotmail-targeted stealer log files like this one. If your Microsoft account credentials appeared in this dump, you will know immediately so you can change your password, review account activity, and revoke any unauthorized access before attackers lock you out permanently. Scan your email free at HEROIC right now.
Breach Breakdown
1,064 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds