If You Use Hotmail, the 190K HQ Combo Leak Affects You
HEROIC has confirmed the existence of a stealer log combolist titled "190K HQ Hotmail Combo Test" that was uploaded to Telegram in September 2024. This curated collection specifically targets Hotmail (Microsoft) accounts and contains 155,041 credential records—email addresses, plaintext passwords, and the URLs where each credential was captured from infected users' browsers.
Plaintext Hotmail Passwords: No Cracking Required
The "HQ" label means these credentials have been filtered for quality—and every password is stored in readable plaintext. For Hotmail users in this dump, the implications are direct: anyone who downloads this file can attempt to log into your Microsoft account, access your Outlook inbox, OneDrive files, and any linked Microsoft service. No technical expertise is needed.
What Was Exposed
- Email Addresses – Hotmail and Outlook accounts that serve as gateways to the entire Microsoft ecosystem
- Plaintext Passwords – Unencrypted credentials for 155,041 individual Microsoft accounts
- URLs – Login pages and web services revealing where each credential was harvested
Your Hotmail Password Likely Protects More Than Email
Microsoft accounts are deeply integrated into people's digital lives. A compromised Hotmail password can give attackers access to Outlook email, OneDrive cloud storage, Microsoft 365 documents, Xbox accounts, and Skype. If you use that same password elsewhere—for banking, shopping, or social media—credential stuffing tools will find those matches quickly, turning one compromised Hotmail login into a full-spectrum account takeover.
How This Hotmail Combolist Was Built
This collection was assembled from data stolen by infostealer malware running on real users' devices. Malware families like Lumma, Raccoon, and Vidar infect computers through phishing emails, fake software updates, and malicious browser extensions. They silently extract saved credentials from browsers like Chrome, Edge, and Firefox, then filter and organize the results by email provider—in this case, Hotmail and Outlook accounts—to create high-value targeted combolists for distribution on Telegram.
Check If Your Credentials Were Exposed
If you have ever used a Hotmail or Outlook email address, this dump demands your attention. HEROIC's breach scanner searches over 400 billion compromised records to identify exactly which breaches and leaks include your data. Search your email now to learn whether your Hotmail credentials were exposed in this 190K HQ combo or any other known breach.
Breach Breakdown
155,041 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds