Search Your Email: The hotmail TXTVALID Leak Exposed 99 Accounts
In April 2026, HEROIC analysts found a small stealer log labeled "hotmail TXTVALID" shared on Telegram. It contained 99 records, each pairing a Hotmail email address with a plaintext password and the login URL it was verified against.
Why This Is Dangerous
The "TXTVALID" label means these 99 email and password combinations have already been checked and confirmed to still work. That makes this small file more dangerous than its size suggests, since attackers know every entry is a live account rather than an outdated one.
What Was Exposed
- Hotmail email addresses tied to the affected accounts
- Plaintext passwords confirmed to still be valid
- Login URLs showing which site each password was verified on
Why This Matters
Because these credentials were validated, anyone in this batch faces an immediate risk of account takeover, and if the password was reused elsewhere, credential stuffing can spread that risk to other accounts too.
How the hotmail TXTVALID List Was Built
Stealer malware first collects saved passwords from infected devices, then criminals often run a validation pass to filter out logins that no longer work, keeping only the "TXTVALID," or confirmed valid, entries. This 99-record file is the result of that filtering process.
Check If You Are Affected
Searching your own email takes seconds and could save you from a validated leak like this one. HEROIC's free breach scanner checks your address against more than 400 billion leaked records, so you can confirm your status right now.
Breach Breakdown
99 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds