The Hotmail Fresh B4_Jx Leak Gives Attackers 295 Ready Logins
HEROIC analysts found a combolist named Hotmail Fresh B4_Jx, uploaded to Telegram on March 28, 2026, containing 295 records of email addresses, plaintext passwords, and the URLs each login was meant for. The name suggests a focus on Hotmail and similar webmail accounts. Why This Is Dangerous: Because the passwords are stored in plaintext, attackers can use the 295 credential pairs in this file immediately, without cracking anything first. Small file size does not mean small risk: every record represents a real account an attacker can try to access right now. What Was Exposed: Email addresses, plaintext passwords, and the login URLs tied to each account, giving attackers a ready-made login attempt for every entry. Why This Matters: Webmail accounts like these are often used to reset passwords on other services, so a compromised email can become the key to unlocking someone's banking, shopping, or social media accounts as well. Attackers with this list have everything they need to attempt account takeover on each of these 295 accounts today. How This Combolist Was Built: Files described as fresh, like Hotmail Fresh B4_Jx, are typically pulled from recent stealer malware infections or newly compiled breach data, then packaged and shared on Telegram to appeal to buyers looking for currently active credentials. Check If You Are Affected: HEROIC's free breach scanner checks your email against more than 400 billion leaked records. Run a free scan today to see if your Hotmail or other email account has been exposed.
Breach Breakdown
295 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds