Identity Theft Risk Rises After the 19k Hotmail Combo HQ Leak
On January 30, 2025, HEROIC analysts identified a combolist file named "19k Hotmail Combo hq" circulating on Telegram. The "hq," or high quality, label is how criminals market these files to each other. The file contained 19,499 records, each pairing a Hotmail or Outlook email address with a plaintext password and the associated login URL. Why This Is Dangerous: A file marketed as high quality typically means the credentials inside have been checked and are believed to still work, making the list more dangerous than an unverified dump. With the passwords stored in plaintext, anyone who obtains the file can immediately attempt to log into each account. What Was Exposed: The file contains email addresses, plaintext passwords, and the URLs each login was tied to. Why This Matters: Email accounts are often the key to resetting passwords on other services, so a compromised Hotmail or Outlook login can quickly cascade into other accounts being taken over. Combined with password reuse, a file like this gives criminals a strong starting point for credential stuffing, identity theft, and financial fraud. How This Combolist Was Likely Built: Files labeled "combo hq" are usually built by taking a raw combolist from older breaches or stealer malware, then running it through a checker tool that verifies which pairs still successfully log in, and repackaging the verified subset as a premium list. Check If You're Affected: If you use a Hotmail or Outlook account or reuse the same password on multiple sites, HEROIC's free breach scanner searches more than 400 billion leaked records, including verified combolists like this one, so you can act before someone else does.
Breach Breakdown
19,499 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds