One Telegram Post. 343 Hotmail Fresh B4_Jx Logins Now Exposed.
In late April 2026, HEROIC analysts identified a second, smaller file also named Hotmail Fresh B4_Jx being shared on Telegram. This upload contained 343 records, each pairing an email address with a plaintext password and the URL the login was captured from, distinct from a related, larger file bearing the same name. Why This Is Dangerous: Small file size does not mean small risk. Every password in this file is stored in plain, unencrypted text, so anyone who downloads it can immediately attempt to log in with these credentials on Hotmail, Outlook, or any other account tied to the same email address. What Was Exposed: - Email addresses - Plaintext passwords - Login URLs for each account Why This Matters: Sellers and traders on Telegram often release the same stolen data in multiple smaller batches to test demand or avoid detection. Regardless of batch size, if any of these 343 people reused their password elsewhere, they face real risk of credential stuffing, account takeover, identity theft, and financial fraud. How a Combolist Like This Works: Files like this are typically drawn from stealer malware logs or recycled breach data, sorted by email provider, and uploaded in smaller batches under a shared name to make them easier to move quickly through Telegram trading channels. Smaller, "fresher" batches are often marketed as more valuable because the credentials are less likely to have already been changed. Check If You Are Affected: Search your email address using HEROIC's free breach scanner, which checks against more than 400 billion exposed records, including this file. If your account shows up, change the password immediately and anywhere else you have reused it.
Breach Breakdown
343 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds