Hotmail Fresh Combolist Exposes 848 Plaintext Passwords
HEROIC analysts found a combolist called "Hotmail Fresh" uploaded to a Telegram channel on March 16, 2026, containing 848 records of email addresses and plaintext passwords tied to Hotmail accounts.
Why This Is Dangerous
Every password in this file is stored in plaintext, so an attacker can use the credentials the moment they download the list. No cracking, no guessing, just a direct email and password combination ready to try against Hotmail, Outlook, and any other service where the same login might work.
What Was Exposed
- Email addresses
- Plaintext passwords
- Associated URLs
Why This Matters
A list of 848 working credentials is enough to fuel a credential stuffing campaign, where attackers test each login against banking sites, shopping platforms, and social media accounts. Anyone in this batch who reused their Hotmail password elsewhere faces a direct risk of account takeover, followed by identity theft or financial fraud.
How Combolists Work
A combolist pairs email addresses or usernames with passwords, usually pulled from older breaches, phishing pages, or malware infections and repackaged for distribution on Telegram. Labels like "Hotmail Fresh" are used to signal that the data has not yet circulated widely, which makes it more valuable to attackers since fewer victims have had time to change their passwords.
Check If You Are Affected
If you use Hotmail, Outlook, or a similar email service, check now whether your credentials appear in this leak. HEROIC's free breach scanner searches more than 400 billion leaked records, so you can find out quickly and update any passwords you have reused.
Breach Breakdown
848 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds