Hotmail Users Targeted in the hotmail_hits 2 Leak of 139 Accounts
HEROIC analysts identified a combolist called hotmail_hits 2 that was uploaded to a Telegram channel on July 4, 2026. The file contains 139 records pairing Hotmail email addresses or usernames with plaintext passwords, along with URLs identifying the accounts they belong to. Why This Is Dangerous This leak specifically targets Hotmail and Outlook users, meaning the people affected are likely to have their email inbox exposed rather than just a single account on another site. Because the passwords are stored in plaintext, anyone who obtains the file can log in immediately without any additional effort. What Was Exposed Email addresses Plaintext passwords URLs tied to each account Why This Matters Email accounts are often the key to resetting passwords on other services, so a compromised Hotmail inbox can quickly turn into a compromised bank account, shopping account, or social media profile. Attackers frequently target webmail providers specifically because gaining access to one inbox can unlock access to many other accounts tied to that email address. How Combolist Attacks Work A combolist bundles usernames or emails with matching passwords, typically gathered from previous breaches, phishing campaigns, or malware infections, then compiled into one file for resale or free distribution. Because there is no encryption to break, a file like hotmail_hits 2 can be used within minutes of appearing on a Telegram channel or dark web forum. Check If You Are Affected If you use a Hotmail or Outlook account, it is worth checking whether your email appears in this 139-record leak. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, so you can quickly find out if you were exposed and secure your inbox.
Breach Breakdown
139 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds