If You Use Live.com, This 1,385-Account Password Leak Should Worry You
In June 2026, HEROIC analysts found a combolist labeled Live.com circulating on Telegram, containing 1,385 records of email addresses and plaintext passwords tied to Live.com and Microsoft accounts, along with associated URLs.
Why This Is Dangerous
Live.com accounts are often connected to Microsoft services including Outlook email, OneDrive storage, and Xbox profiles, meaning a single compromised login can expose far more than just an inbox. With plaintext passwords already confirmed against Live.com, attackers can log in directly without needing to crack or guess anything.
What Was Exposed in the Live.com Leak
- Email addresses
- Plaintext passwords
- Associated URLs
Why This Matters
Because Live.com and Microsoft accounts are often used as a single sign-on for multiple services, gaining access to one can give an attacker a path into email, cloud storage, and connected apps all at once. If you reuse your Live.com password elsewhere, this leak of 1,385 accounts increases the risk of credential stuffing attacks succeeding against your other accounts too.
How a Combolist Like This Works
Files tagged to a specific domain like Live.com are usually created by filtering a larger pool of stolen credentials down to just the entries confirmed to work against that service's login page. This targeted approach makes the list more valuable to buyers since every entry is verified against a real, well-known platform rather than being an unconfirmed mix.
Check If You Are Affected
If you have a Live.com, Outlook, or Microsoft account, it is worth checking whether your credentials appear in this leak. HEROIC's free breach scanner searches more than 400 billion leaked records to tell you in seconds if your information has been exposed.
Breach Breakdown
1,385 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds