The Hotmail Stealer Log Put 360 Stolen Email and Password Pairs Online Last Week
HEROIC analysts identified a targeted stealer log file uploaded to Telegram on June 22, 2025 that exposed 360 Hotmail account credentials. The file, distributed by an anonymous Telegram user under the name "315 hotmail," contained email addresses, plaintext passwords, and endpoint URLs harvested specifically from Microsoft Hotmail and Outlook accounts. While small in volume, this type of targeted account dump is designed for precision attacks against Microsoft ecosystem accounts, including OneDrive, Xbox, and linked Microsoft 365 services.
Why a Targeted Hotmail Credential Dump Is a Significant Threat
Hotmail and Outlook accounts are gateway credentials to the entire Microsoft ecosystem. A compromised Microsoft account does not just expose email. It can provide access to OneDrive cloud storage, Microsoft 365 documents, Xbox Game Pass, linked payment methods, and any service that uses Microsoft login for authentication. Targeted Hotmail dumps are particularly valuable to attackers because victims often link their Microsoft account to work devices, enabling corporate espionage or ransomware deployment through a personal account compromize. The small size of this file also suggests it may be a curated, high-quality subset rather than a random sample.
Data Exposed in the Hotmail Telegram Stealer Log
The following data types were confirmed in this stealer log upload:
- Email Addresses (Hotmail and Outlook accounts)
- Plaintext Passwords (unencrypted, directly usable for login)
- URLs (specific Microsoft services and other platforms the victims accessed)
How Attackers Exploit Stolen Hotmail Credentials
Microsoft account credentials unlock a wide range of attack paths. Here is the exploitation chain once a Hotmail login is obtained:
- Credential stuffing: The same email and password combination is tested across hundreds of non-Microsoft services simultaneously, exploiting password reuse to compromise banking, streaming, and social media accounts.
- Account takeover: Once inside the Microsoft account, attackers add their own recovery phone number, removing the victim's ability to regain access through standard recovery methods.
- Identity theft: OneDrive files, Outlook email history, and linked contacts reveal enough personal information to file fraudulant credit applications, tax returns, or government benefit claims in the victim's name.
- Financial fraud: Stored Microsoft payment methods and linked Xbox or Microsoft Store credits are harvested immediately, and connected bank account confirmations in the inbox enable targeted phishing against the victim's financial institutions.
What Is a Platform-Targeted Stealer Log and Why Hotmail Is a Common Target
Platform-targeted stealer logs are created when infostealer operators filter their raw harvest by domain type. Instead of selling a mixed combolist, they extract only records from a specific platform, like Hotmail or Outlook, and package them separately. This filtering is done because platform-specific credentials command higher prices and are more useful for attackers running targeted campaigns against that platform's user base. Microsoft accounts are particularly prized because of the Microsoft ecosystem's breadth, the prevalence of Microsoft accounts as corporate identities, and the tendency of long-term Hotmail users to have never updated their passwords. Malware like Lumma Stealer, Vidar, and MetaStealer all support Hotmail-specific extraction, making this type of targeted file increasingly common in Telegram-based criminal markets. The June 2025 date on this file means the 360 affected accounts have been in criminal circulation for months without their owners necesarily knowing.
Check If Your Hotmail Account Was in This Breach
HEROIC's free breach scanner checks your email against more than 400 billion exposed records, including Hotmail-targeted stealer log files like this one. If your Microsoft account credentials appeared in this dump or any other breach in our database, you will know immediately so you can secure your account, revoke access, and change your password before attackers do. Run a free breach scan at HEROIC now.
Breach Breakdown
360 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds