How Malware Led to 3,551 Stolen Logins in the Hotmail Combo
HEROIC's threat monitoring systems flagged a Hotmail-focused credential combo list attributed to the actor crasco_owner on Telegram. The file, marketed as a high-quality collection, contains 3,551 stolen records. Each entry pairs a Hotmail email address with the user's plaintext password and the URL of the login page where the credential was intercepted. The data originated from infostealer malware that ran undetected on victims' computers.
Exposed in Plaintext: No Protection Whatsoever
These are not hashed or encrypted passwords. Every single credential in the crasco_owner Hotmail combo is stored as raw, readable text. Any person who obtains this file can immediately attempt to log in to the associated accounts. Plaintext password exposure eliminates the need for password-cracking tools and drastically shortens the time between data theft and account compromise.
What Was Exposed
- Email Addresses — Hotmail accounts that often serve as primary login credentials for Microsoft services
- Plaintext Passwords — passwords captured exactly as users typed them, with no obfuscation
- URLs — the specific web pages where each credential was silently stolen
From One Stolen Password to a Full Account Takeover
Credential stuffing is the natural next step after a leak like this. Automated bots take each email-password pair and test it against popular services — online banking, e-commerce platforms, corporate email, and cloud storage. Because password reuse remains widespread, a significant percentage of these attempts succeed on the first try. Hotmail accounts are especially valuable targets since they often link to Microsoft 365, OneDrive, and other integrated services.
The Infostealer Malware Pipeline
Every record in this combo list traces back to a device infected with infostealer malware. The attack chain typically begins with a deceptive download — a fake game crack, a trojanized productivity tool, or a phishing attachment. Once executed, the malware quietly reads saved passwords from browsers like Chrome, Firefox, and Edge. It packages these credentials along with cookies and session data, then uploads the bundle to a command server. Actors like crasco_owner then curate and redistribute these logs to Telegram channels.
Check If Your Credentials Were Exposed
HEROIC has incorporated the crasco_owner Hotmail combo into its comprehensive breach database, which tracks more than 400 billion compromised records. Use HEROIC's free breach scanner to search for your email address or password. If your Hotmail credentials appear in this dump, change your password immediately, enable two-factor authentication, and review your account for unauthorized activity.
Breach Breakdown
3,551 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds