Inside the HOTMAIL EIGZ_V1 Logs: 1,460 Passwords Harvested
Inside the HOTMAIL EIGZ_V1 Logs: 1,460 Passwords Harvested
On May 14, 2026, HEROIC analysts identified a stealer log named "HOTMAIL EIGZ_V1" after a Telegram user uploaded it to a channel used for distributing stolen credentials. The file contains 1,460 records, each one pairing an email address with a plaintext password and the URL of the site the credentials were captured from. Every one of those 1,460 logins is immediately usable by anyone who gets hold of the file, no extra work required.
Why This Is Dangerous
Because these passwords were harvested in plaintext, there is no encryption layer for an attacker to defeat. The malware behind logs like this one grabs the password exactly as it was typed, then tags it with the site it belongs to. That means a criminal can move straight from opening the file to attempting a login, with the target already identified for them.
What Was Exposed
- Email addresses (Hotmail accounts)
- Plaintext passwords
- URLs showing where each password was used
Why This Matters
With 1,460 accounts involved, this is one of the larger stealer logs HEROIC has tracked from this uploader. Anyone in the file faces immediate account takeover risk on the listed sites, and broader exposure through credential stuffing if a password was reused elsewhere. A compromised Hotmail account can also open the door to other services that rely on it for password recovery.
How the HOTMAIL EIGZ_V1 Logs Were Harvested
Files like this come from malware quietly installed on victims' computers, built specifically to read saved passwords out of the browser and record whatever gets typed into a login form. The malware pairs each password with the site's URL and reports everything back to whoever controls the infection. From there, the collected data is packaged into a log file and uploaded to Telegram, where it can spread quickly to anyone watching the channel. The larger the number of infected devices feeding into one log, the bigger the record count, which is likely why this batch reached 1,460 entries.
Check If You Are Affected
If you use a Hotmail account, checking your exposure now is the safest move. HEROIC's free breach scanner searches more than 400 billion leaked records, including stealer logs like this one, to show you whether your email or password has surfaced anywhere on the dark web. Run a free scan and update any password that comes back as compromised.
Breach Breakdown
1,460 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds