The HotmailFxxlp Combolist Put 1,873 Email and Password Pairs Online
In May 2026, HEROIC analysts discovered a combolist labeled "5000x HotmailFxxlp" shared on Telegram. Despite the name suggesting a larger file, the list actually contained 1,873 usable records pairing email addresses with plaintext passwords. Why This Is Dangerous: The file's plaintext passwords mean no cracking or decryption is required to use them. Anyone with access to this list can immediately try each email and password pair against Hotmail, Outlook, and any other service the person might use. What Was Exposed: The HotmailFxxlp list contains email addresses, plaintext passwords, and URLs tied to the accounts. Why This Matters: Because so many people use their email password across other accounts, a leaked webmail credential can quickly become a master key. Attackers can reset banking passwords, access saved payment details, and impersonate the account owner, turning a modest 1,873-record leak into a much larger identity theft risk. How This Kind of Combolist Works: Combolists like this one are built by aggregating credentials from earlier, often unrelated leaks and formatting them into simple email and password files. They're traded freely on Telegram because they take seconds to search and require no special tools to exploit. Check If You Are Affected: If you use a Hotmail or Outlook address, it's worth checking now. HEROIC's free breach scanner searches more than 400 billion leaked records, including combolists like this one, to show you exactly what's exposed.
Breach Breakdown
1,873 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds