Hotmail.jp Leak Means 4,216 Japanese Accounts Are Ready to Steal
HEROIC analysts identified a stealer log collection titled "hotmail.jp AnonymousRichard" that appeared on a Telegram channel in June 2026. The dataset, attributed to a threat actor operating under the alias AnonymousRichard, contains 4,216 compromised credential records specifically targeting users of Microsoft's Hotmail.jp email service. Each record exposes an email address, a plaintext password, and the URL where those credentials were stored in the victim's browser. The Japan-specific focus makes this dump a precision tool for targeted account takeover.
Why Plaintext Passwords Put Japanese Email Users at Immediate Risk
All 4,216 passwords in this collection are stored in plaintext — captured exactly as the victims entered them and delivered without any encryption or obfuscation. An attacker does not need to crack, decode, or process these credentials in any way. Each password is immediately usable for logging into the associated Hotmail.jp account and any other service where the victim has reused the same credentials.
Hotmail.jp accounts are particularly valuable because Microsoft email addresses frequently serve as the primary recovery mechanism for other online services. An attacker who controls a victim's Hotmail.jp inbox can intercept password-reset emails, verification codes, and security alerts from banks, e-commerce platforms, and social media services. This single point of compromise grants the attacker influence over the victim's entire connected digital ecosystem.
What Was Exposed in the Hotmail.jp Dump
- Email Addresses — 4,216 Hotmail.jp email addresses belonging to Japanese users, each one serving as a primary login credential and recovery address across numerous online services.
- Plaintext Passwords — Completely unencrypted passwords extracted from browser credential databases on infected devices, ready for instant exploitation.
- URLs — The exact login pages where each credential pair was saved, providing attackers with a detailed map of every service the victim accessed.
Why 4,216 Targeted Credentials Threaten Entire Account Ecosystems
When a stealer log specifically targets a single email domain like Hotmail.jp, the resulting data is highly concentrated and immediately actionable. Attackers do not need to filter through irrelevant entries — every record in this dump points to a Japanese Microsoft email user. This focus allows for efficient, automated credential-stuffing campaigns against Japanese banking platforms, e-commerce sites like Rakuten and Amazon Japan, and mobile payment services.
The threat extends beyond the 4,216 directly compromised accounts. Password reuse rates among email users consistently exceed 60%, meaning attackers can expect thousands of additional account compromises simply by testing the stolen Hotmail.jp credentials against other popular services. Each compromised account can also be leveraged for further attacks, including phishing campaigns sent from legitimate addresses that bypass spam filters and trust barriers.
How Stealer Logs Target Specific Email Domains
Infostealer malware captures every credential stored in a victim's browser, regardless of the email domain or service provider. However, when operators compile and distribute the stolen data, they often sort it by email domain to create targeted packages. The "hotmail.jp" label on this collection indicates that the operator filtered a larger credential harvest specifically for Japanese Microsoft email accounts, creating a curated dataset with a clear geographic and service-provider focus.
The attribution to "AnonymousRichard" suggests an individual operator or small group that regularly compiles and distributes stealer log collections through Telegram. These operators often build reputations within credential-trading communities by consistently delivering fresh, accurately labeled data. Their Telegram channels attract buyers who are specifically looking for credentials tied to certain countries or email providers, creating a marketplace where geographic precision commands a premium.
Check If Your Hotmail.jp Credentials Were Compromised
If you use a Hotmail.jp email address or any Microsoft email service in Japan, this leak represents a direct and immediate threat. The credentials were harvested in June 2026 and are almost certainly still active for victims who have not yet changed their passwords.
Use HEROIC's free breach scanner to check whether your email address or passwords appear in the Hotmail.jp AnonymousRichard dump or across our database of 400B+ compromised records. If your credentials are found, change your Microsoft account password immediately, enable two-factor authentication, review your account's recent sign-in activity for unauthorized access, and check for any mail-forwarding rules or connected apps that an attacker may have configured to maintain persistent access.
Breach Breakdown
4,216 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds