The Hotmail Fresh 2 Leak Contains Exactly 680 Stolen Logins
In March 2025, HEROIC analysts identified a combolist file uploaded to a Telegram channel under the label "hotmail fresh 2." The file contained exactly 680 records pairing Hotmail and Outlook email addresses with plaintext passwords, along with the URLs of the accounts each credential belonged to. Why This Is Dangerous An email account is often the key that unlocks everything else. Anyone with access to a Hotmail or Outlook inbox can reset passwords on banking, shopping, and social media accounts linked to that address. Because the passwords in this file are stored in plaintext, whoever holds this list can log into these 680 accounts immediately, no cracking required. What Was Exposed Email addresses Plaintext passwords URLs of the accounts tied to each credential pair Why This Matters For the 680 people in this file, the risk goes beyond the email inbox itself. If any of these passwords were reused on other sites, attackers can use automated credential stuffing tools to break into those accounts too. Since email is frequently used to reset other passwords, one compromised inbox can cascade into account takeover, financial fraud, or identity theft. How Combolist Breaches Work A combolist pairs email addresses or usernames with passwords, usually gathered from older leaks, stealer logs, or phishing campaigns. Sellers label these files as "fresh" to signal the credentials have not yet been widely used, making them more valuable when traded on Telegram channels and dark web forums. Check If You Are Affected HEROIC's free breach scanner checks your email address against more than 400 billion breached records, including combolists like this one. Run a free scan today to see if your credentials were exposed.
Breach Breakdown
680 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds