The Hotmail Hits 2 Combolist: 1,239 Passwords Just Surfaced Online
1,239 Passwords From the Hotmail Hits 2 Combolist Surface HEROIC analysts found a combolist labeled "hotmail hits 2" uploaded to Telegram on December 8, 2024. The file contains 1,239 records pairing email addresses, largely Hotmail and Outlook accounts, with plaintext passwords and associated URLs. Why This Is Dangerous Because the passwords are stored in plaintext and focused specifically on webmail accounts, attackers can immediately try logging into each account without any additional cracking. A compromised email account can also be used to reset passwords on other services tied to that inbox. What Was Exposed Email addressesPlaintext passwordsAssociated URLs Why This Matters Email accounts act as a gateway to almost everything else online, from banking to social media password resets. If any of the 1,239 people in this list reused their email password elsewhere, attackers could use that single login to take over multiple accounts, leading to financial fraud or identity theft. How a Combolist Works A combolist is a compiled file of combo entries, an email paired with a password, often filtered to focus on a specific provider like Hotmail, as this one appears to be. Criminals build these targeted lists because webmail credentials are especially useful for resetting passwords on other connected accounts. Check If You Are Affected If you use a Hotmail or Outlook address and think your credentials might be part of this combolist, HEROIC's free breach scanner checks against more than 400 billion leaked records. Run a free scan and change your password if it's been exposed.
Breach Breakdown
1,239 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds