Breach Intelligence Report 06 Apr 2026

The Hotmail Dump: 1,064 Stolen Login Credentials Hit Telegram in June 2025

HEROIC
HEROIC Threat Intelligence Team
Email Addresses Plaintext Password Urls
Stealer Logs 932 hotmail uploaded by a Telegram User
Your email may be in this breach. Check in 5 seconds — free, no signup required.
Scan Email →
Records Exposed 1,064
Source Type Stealer log
Origin United States
Password Type plaintext

HEROIC analysts identified a Hotmail-targeted stealer log file uploaded to Telegram on June 22, 2025 that exposed 1,064 records. The file, distributed by an anonymous Telegram user under the designation "932 hotmail," contained email addresses, plaintext passwords, and endpoint URLs harvested specifically from Microsoft Hotmail and Outlook accounts. This is the second Hotmail-targeted stealer log from the same date, suggesting an operator was actively filtering and packaging platform-specific credentials from a larger raw harvest on that day.


Why Platform-Specific Hotmail Credential Dumps Are Particularly Dangerous

Hotmail and Outlook accounts have been Microsoft's consumer email platform for decades, and many long-term users have never changed their original passwords. This makes Hotmail-specific credential dumps especially effective for attackers: a significant portion of exposed passwords are likely still active. Beyond email access, a compromised Microsoft account unlocks OneDrive, Microsoft 365, Xbox, Bing, and any third-party service that uses Microsoft SSO for sign-in. Attackers who specialise in Microsoft account fraud seek these targeted dumps precisely because the blast radius of a single compromised account extends across the entire Microsoft product ecosystem.


Data Exposed in the 932 Hotmail Telegram Stealer Log

The following data types were confirmed in this stealer log upload:

  • Email Addresses (Hotmail and Outlook accounts specifically targeted)
  • Plaintext Passwords (unencrypted, no cracking required)
  • URLs (specific services the victims were logged into at the time of infection)

What Happens After Stolen Hotmail Credentials Hit Telegram

Once a targeted credential file surfaces in Telegram, the exploitation timeline is fast. Here is the typical attack progression:

  • Credential stuffing: Each of the 1,064 email and password pairs is tested against Microsoft login systems and dozens of other platforms that accept Microsoft account credentials, targeting password reuse across services.
  • Account takeover: Successful logins result in immediate account lockout of the legitimate owner by adding an attacker-controlled recovery email and phone, making standard recovery imposible without contacting Microsoft support.
  • Identity theft: Outlook inbox access reveals bank statement notifications, linked service confirmations, and personal correspondence, providing attackers with a comprehensive picture of the victim's identity for use in fraud applications.
  • Financial fraud: Microsoft Wallet, stored payment methods, and Xbox credits are drained immediately, while inbox access to bank notification emails enables targeted phishing of the victim's financial institutions.

What Is a Numbered Hotmail Stealer Log and How Are They Created

Stealer log operators frequently name their files with a number followed by the target platform, such as "932 hotmail." The number typically refers to the original file batch or pack number in the operator's distribution system, not the record count. These files are assembled by filtering raw infostealer harvest data by email domain. When malware like Lumma Stealer, RedLine, or Vidar infects a device and finds saved Hotmail or Outlook credentials in the browser, those entries are harvested alongside all other data. Operators then run domain filters across thousands of raw logs to extract only Microsoft-domain credentials, which they sell or distribute as a premium product. The same-date upload as the earlier "315 hotmail" file suggests both came from the same operator processing a single day's harvest. Together, these two files exposed over 1,400 Hotmail accounts on a singl day in June 2025.


Check If Your Microsoft Account Was Exposed in This Breach

HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including Hotmail-targeted stealer log files like this one. If your Microsoft account credentials appeared in this dump, you will know immediately so you can change your password, review account activity, and revoke any unauthorized access before attackers lock you out permanently. Scan your email free at HEROIC right now.

Breach Breakdown

Domain 932 hotmail uploaded by a Telegram User
Leaked Data Email Addresses,Plaintext Password,URLs
Password Types plaintext
Date Leaked 06 Apr 2026
Check in 5 seconds

1,064 passwords exposed. Is yours one of them?

Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.

All information submitted is Private and Secure. We do not sell or share email addresses. By searching, you agree to HEROIC's Privacy Policy and Terms of Service.

Free forever · No account required · Results in seconds

Private & Secure No Account Needed 3,664 scanned today
Breach Rank #N/A by affected users
Impact Score
0
sensitivity + scale + recency
Est. Financial Impact $7.7K fraud, phishing & misuse risk
Scan your email Free →
Scan to sign up

Scan to sign up instantly

24/7 Dark Web Monitoring
Instant Breach Alerts
Secure Data Protection
Your Data is at Risk

Your Personal Information is Exposed

We found your data exposed in multiple breaches. This includes:

  • Email addresses
  • Passwords
  • Phone numbers
  • Financial information
Secure My Information Now

Your information is protected by enterprise-grade security

Your Breach Details

Date:
Severity:
Records Exposed:

Your Exposed Information

Your Risk Level

How This Affects You

Full Breach Details

Premium Insights

Unlock Critical Security Information

Create a free account to access:

  • Full Breach Impact Analysis
  • Identity Theft Risk Score
  • Exposed Credentials Details
  • Personalized Security Recommendations
Create Free Account

Identity Theft Risk Score

Risk Score: 8.7/10 - Critical

Data Exposure Analysis

Passwords Critical
Financial High
Personal Medium
Social High
Security Critical

Breach Timeline Analysis

March 2024 Multiple credentials exposed in recent data breach
January 2024 Password found in dark web marketplace
December 2023 Personal information leaked in major security incident

Security Recommendations

High Priority
Password Security

Critical: Change compromised passwords immediately and enable 2FA on all accounts

Important
Financial Protection

Monitor credit reports and set up fraud alerts with major credit bureaus

Recommended
Identity Protection

Enable advanced identity monitoring and dark web surveillance