The Hotmail UHQ Leak Gave Attackers 813 Ready-to-Use Logins
On 6 June 2025, HEROIC analysts tracked a combolist called "Hotmail UHQ" uploaded to a Telegram channel that trades stolen credentials. The file contained 813 records pairing email addresses with plaintext passwords and the URLs of the accounts they open.
Why This Is Dangerous
"UHQ" is shorthand sellers use for "ultra high quality," meaning the credentials have likely been checked and confirmed to still work at the time of listing. Combined with plaintext passwords that require no cracking, this gave attackers 813 ready-to-use logins the moment the file appeared.
What Was Exposed
- Email addresses
- Plaintext passwords
- URLs identifying the account each credential pair belongs to
Why This Matters
Because these credentials were advertised as verified and working, the accounts behind them face immediate risk rather than the lower odds that come with older, unverified data. Anyone among the 813 exposed accounts should assume their password is already compromised.
How Combolists Work
Combolists labeled "UHQ" or "high quality" have typically been run through a checker tool that confirms each email and password pair still successfully logs in before the list is sold or shared. This makes them more dangerous than random unverified combolists, since attackers know the credentials work without having to test them first, letting them move straight to using the accounts.
Check If You Are Affected
Search your email address against HEROIC's database of more than 400 billion leaked records with a free scan to see if it appears in the "Hotmail UHQ" combolist or any other exposure.
Breach Breakdown
813 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds