The Live.com Leak Contains Exactly 7,524 Email/Password Pairs
The Live.com Combolist Contains Exactly 7,524 Email and Password Pairs HEROIC analysts identified a combolist referencing "live.com" uploaded to Telegram on December 17, 2024. The file contains precisely 7,524 records pairing email addresses with plaintext passwords, along with the URLs those accounts were tied to. Why This Is Dangerous Live.com is a Microsoft sign-in domain, meaning accounts in this list can connect to email, cloud storage, and other Microsoft services. With passwords stored in plaintext, attackers can use every one of the 7,524 entries immediately without needing to crack anything. What Was Exposed Email addressesPlaintext passwordsAssociated URLs Why This Matters Because Microsoft accounts often link to other services and devices, a compromised live.com login can open the door to far more than a single inbox. Anyone in this list who reused their password elsewhere risks credential stuffing, account takeover, or identity theft. How a Combolist Works A combolist compiles login pairs, an email or username matched with a password, into one file criminals can run through automated tools that test each pair against many websites. Lists targeting a specific domain like live.com let attackers focus their efforts on one service at a time. Check If You Are Affected If you have a live.com or Microsoft account and think your credentials might be exposed, HEROIC's free breach scanner checks against more than 400 billion leaked records. Run a free scan and update your password if it turns up.
Breach Breakdown
7,524 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds