Hotmail Users Targeted in a 1,642-Account Combolist Leak
HEROIC analysts identified a combolist labeled Hotmail combo, uploaded by a Telegram user, containing 1,642 records dated September 30, 2024. The file pairs Hotmail email addresses with plaintext passwords and the URLs those credentials unlock. Why this is dangerous: this list specifically targets Hotmail and Outlook users, meaning the attacker already knows the email provider and can focus efforts on Microsoft account takeover, from Outlook mail to OneDrive files and any other service tied to that same login. Because the passwords are stored in plaintext, no additional cracking is needed before they can be used. What was exposed: Hotmail email addresses, plaintext passwords, and the URLs linked to each credential pair. Why this matters: Microsoft accounts often connect to email, cloud storage, and other logins through the same password. If this password was reused, attackers can pivot from one Hotmail account into credential stuffing attempts across banking, shopping, and social media sites, opening the door to identity theft and financial fraud. How combolists work: a combolist is a curated set of email and password combinations, often built by filtering older breach data or stealer logs down to one email provider or region. Attackers favor provider-specific lists like this one because it lets them target Microsoft account recovery and login flows more precisely, increasing the odds that a stolen password still works. Check if you are affected: HEROIC's free breach scanner checks your email against a database of more than 400 billion leaked records, including combolists like this one. Run a scan to see if your Hotmail account was exposed and learn which passwords to update.
Breach Breakdown
1,642 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds