Inside the Hotmail Combolist: How 918 Login Pairs Leaked Online
HEROIC analysts discovered a small combolist made up entirely of Hotmail accounts, uploaded to a Telegram channel on May 28, 2026. The file contains 918 records pairing email addresses with plaintext passwords and the URLs those credentials unlock. Why This Is Dangerous: These aren't guessed passwords, they're real ones, already matched to real Hotmail addresses and the exact login pages they work on. That makes each record ready to use the moment someone downloads the file. What Was Exposed: Every record in this Hotmail file includes the same three pieces of information. - Hotmail email addresses - Plaintext passwords - URLs tied to each login Why This Matters: A file of 918 records is small, but Hotmail and other webmail accounts are often the master key to someone's digital life, tied to banking alerts, password resets, and other accounts. If any of these 918 people reused their Hotmail password elsewhere, attackers can use this file for credential stuffing and account takeover well beyond just email. How a Combolist Like This Works: A combolist is a plain list of email-or-username and password pairs, usually assembled from older leaks or malware infections and shared for free or sold cheaply on Telegram. Even small combolists like this one are traded and tested quickly because they cost attackers nothing to try. Check If You Are Affected: Use HEROIC's free breach scanner to check your Hotmail address against more than 400 billion leaked records and find out if you were one of the 918 people in this file.
Breach Breakdown
918 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds